Ad

CVE-2026-64581

HIGH CVSS 3.1: 7,8 EPSS 0.11%
Обновлено 8 августа 2026
Linux
Параметр Значение
CVSS 7,8 (HIGH)
Уязвимые версии 3.16.52 — 7.2-rc4
Устранено в версии 7.1.6
Поставщик Linux
Публичный эксплойт Нет

В ядре Linux устранена следующая уязвимость: xfrm: исправлено двойное освобождение sk_dst_cache в xfrm_user_policy() xfrm_user_policy() очищает кэш dst сокета с помощью __sk_dst_reset(), то есть неатомарный __sk_dst_set(sk, NULL): он читает sk_dst_cache с помощью rcu_dereference_protected() сохраняет NULL, а dst_release() — старое значение dst. Это безопасно только в том случае, если никакой другой поток одновременно не изменяет sk_dst_cache. Для подключенного сокета UDP, который не удерживается: быстрый путь передачи (udp_sendmsg -> sk_dst_check -> sk_dst_reset) сбрасывает кеш без блокировки с атомарным xchg().

Изменение политики для каждого сокета, участвующее в гонке, может сделать отправка обе стороны наблюдают один и тот же старый dst и каждый dst_release() его, отбрасывая одиночную ссылку сокета дважды и освобождая пакет xfrm_dst, пока на него все еще ссылаются: ОШИБКА: KASAN: использование плиты после освобождения в dst_release Запись размера 4 по адресу ffff88801897b6c0 с помощью задачи эксплойта/155. Отслеживание вызова: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) запись_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Доступен непривилегированному пользователю через пространство имен пользователь+сеть. Используйте атомарный sk_dst_reset(), чтобы очистить и освободить кеш с помощью одиночный xchg(): какая бы сторона ни победила, один раз выпускает dst, другая видит NULL и ничего не делает.

В остальном поведение не меняется.

Показать оригинальное описание (EN)

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently. For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced: BUG: KASAN: slab-use-after-free in dst_release Write of size 4 at addr ffff88801897b6c0 by task exploit/155 Call Trace: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Reachable by an unprivileged user via a user+network namespace. Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.

Характеристики атаки

Способ атаки
Локальный
Нужен локальный доступ
Сложность
Низкая
Легко эксплуатировать
Нужны права
Низкие
Нужны базовые права
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Высокое
Полная утечка данных
Целостность
Высокое
Полная модификация данных
Доступность
Высокое
Полный отказ в обслуживании

Строка CVSS v3.1

Уязвимые продукты 8

Конфигурация От (включительно) До (исключительно)
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.14 7.1.6
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.14 7.2-rc4
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
3.16.52
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.4.163
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
3.18.101
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.1.52
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.4.123
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.9.89