Executive brief
A vulnerability exists in the MediaTek Ethernet driver within the Linux kernel. This component is responsible for managing network connectivity on devices using MediaTek hardware. An exploit could lead to a system crash or unpredictable behavior during network device teardown, potentially impacting the availability of the system.
Technical details
A use-after-free (UAF) vulnerability exists in the mtk_eth_soc driver within the Linux kernel. The root cause is the use of metadata_dst_free() in mtk_free_dev(), which immediately invokes kfree() and bypasses the RCU grace period. In the receive (RX) path, skb_dst_set_noref() creates non-refcounted pointers to this metadata that require RCU protection. If a driver teardown occurs while an skb still holds a pointer to the destination, a UAF is triggered. The fix replaces metadata_dst_free() with dst_release(), ensuring the memory is only freed via call_rcu_hurry() after all RCU readers have finished. This is reachable locally during network interface management operations.
Affected products
- Linux Linux Kernel 6.2 to 7.1
Timeline
- 2026-06-02: other: Patch authored
- 2026-06-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/2d86aeb46d5f69c704065a8c69822582787272a1
- https://git.kernel.org/stable/c/459c6f35c58cf0fd5247e55d73ddaa29571d9b7e
- https://git.kernel.org/stable/c/72775977e89c25c99ee84d2c5baa3f86a8ba5cb4
- https://git.kernel.org/stable/c/80df409e1a483676826a6c66e693dba6ac507751
- https://git.kernel.org/stable/c/e634408d2b0cd939cfe019398a21fb47b7a8ffe3