Use-after-free in Linux kernel - CVE-2026-64123
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information or cause a denial of service.
The vulnerability exists due to a use-after-free in the hsr node table handling code when processing generic-netlink node-list or node-status operations concurrently with RTM_DELLINK teardown. A local user can trigger concurrent netlink operations to disclose sensitive information or cause a denial of service.
The generic-netlink reader accesses node entries under RCU and may retain a node pointer while teardown frees the same entry.
How to mitigate CVE-2026-64123
Sources
- https://git.kernel.org/stable/c/0ea70fb46940620848c08d9d399455c9e82fecdb
- https://git.kernel.org/stable/c/6324423a8e6591f41a16c09a8f9a84e554ac147c
- https://git.kernel.org/stable/c/7713f4aafb577ff49fa67f0488d9c7dddc64d6ce
- https://git.kernel.org/stable/c/8be6685cdd1255bcc85f9b59e4bfc313aefc5c1b
- https://git.kernel.org/stable/c/8c3af18bb0d7c921a5219194037509463eb2ffde
- https://git.kernel.org/stable/c/aaec7096f9961eb223b5b149abe9495525c205d9
- https://git.kernel.org/stable/c/c5580114e0492bcd2e0a37613ed4c311e3fa3d4d