{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-64543",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-19T15:36:31.795Z",
        "datePublished": "2026-07-27T20:10:35.565Z",
        "dateUpdated": "2026-08-19T16:28:28.342Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-19T16:28:28.342Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),\nbut tipc_disc_rcv() still dereferences b->disc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n <IRQ>\n  tipc_disc_rcv (net/tipc/discover.c:149)\n  tipc_rcv (net/tipc/node.c:2126)\n  tipc_udp_recv (net/tipc/udp_media.c:391)\n  udp_rcv (net/ipv4/udp.c:2643)\n  ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n </IRQ>\n Freed by task 181:\n  kfree (mm/slub.c:6565)\n  bearer_disable (net/tipc/bearer.c:418)\n  tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The free side is only reachable through the local TIPCv2 generic-netlink `BEARER_DISABLE` command (or netns teardown); a remote peer can supply the discovery packet that performs the use-after-free access but cannot itself cause `bearer_disable()` to run, so the complete attack requires local access.\nAC:L - The attacker controls both sides of the race — one thread floods TIPC discovery packets at the bearer's UDP port while another disables the bearer — and `bearer_disable()` clears `b->up` and then `kfree()`s the discoverer with no synchronization whatsoever, leaving a wide window that a multi-CPU packet flood hits reliably (a working PoC exists).\nPR:L - `tipc_genl_family` is `.netnsok = true` and the bearer enable/disable ops carry no `GENL_ADMIN_PERM` or other capability check, so an unprivileged user can do everything inside `unshare -Urn` after autoloading tipc via `socket(AF_TIPC, ...)`.\nUI:N - The attacking process performs both the bearer disable and the packet injection itself; no victim action or cooperating user is involved.\nS:U - The corruption stays within the kernel's own security authority — no VM, IOMMU, or hypervisor boundary is crossed.\nC:H - `d->net` is read from the freed slab object and dereferenced as a `struct net *`; after reclaiming the kmalloc-192 allocation with sprayed data the attacker gains a controlled-pointer dereference chain usable for arbitrary kernel memory disclosure.\nI:H - `msg_set_prevnode(buf_msg(d->skb), sugg_addr)` writes a wire-controlled 32-bit value through the dangling `d->skb` pointer, and `tipc_disc_add_dest()` takes a spinlock and increments a counter in freed memory — together a controlled-address/controlled-value write suitable for control-flow hijacking.\nA:H - The use-after-free reliably produces a KASAN slab-use-after-free in softirq context and, on production kernels, a corrupted-pointer dereference or spinlock manipulation on reclaimed memory leading to kernel panic."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/tipc/core.c",
                        "net/tipc/discover.c"
                    ],
                    "versions": [
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "380413cdfd29fb9fa486c82889132b680c4983c5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "f05b3f4c78370469286879c765f5a1dd39dbcd32",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "4da2ac7749411971e1b222b992da5a172ce45f98",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "5e215bf1c47fdddf8203a0fe80a0ed594065f101",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "ec7d54d8cc1723921d671e3272b427c96366506f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "b65289e1c3f352a9f92c6e19713ddd647e033253",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25b0b9c4e835ffaa65b61c3efe2e28acf84d0259",
                            "lessThan": "1579342d71133da7f00daa02c75cebec7372097b",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/tipc/core.c",
                        "net/tipc/discover.c"
                    ],
                    "versions": [
                        {
                            "version": "4.17",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.17",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.265",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.216",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.183",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.145",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.97",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.40",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.5",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "5.10.265"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "5.15.216"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "6.1.183"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "6.6.145"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "6.12.97"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "6.18.40"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "7.1.5"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.17",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b"
                }
            ],
            "title": "tipc: fix use-after-free of the discoverer in tipc_disc_rcv()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}