Junglewise Threat Intelligence

CVE-2026-63801: Linux Kernel TIPC slab-use-after-free in tipc_aead_decrypt_done

CVE-2026-63801 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's TIPC networking protocol could allow a system crash or potentially unauthorized data access. The issue occurs when the system processes encrypted network traffic while a network configuration is being shut down, leading to a 'use-after-free' error. This could be exploited by a remote attacker sending specially crafted network packets to disrupt operations or cause a denial of service.

Technical details

A slab-use-after-free vulnerability exists in the tipc_aead_decrypt_done() function within the TIPC implementation of the Linux kernel. The root cause is a failure to increment the reference count on the network namespace (netns) during the decryption path, unlike the encryption path. When decryption is offloaded asynchronously (e.g., via cryptd), the completion handler may execute after the associated network namespace has been torn down and its memory freed. An attacker can trigger this by flooding a TIPC bearer with crafted encrypted frames while the namespace is being deleted. This results in a kernel oops or memory corruption when the handler attempts to dereference freed 'tipc_crypto' structures. Patches have been released to ensure proper reference counting of the netns during decryption.

Affected products

  • Linux Linux Kernel v7.1-rc7

Timeline

  • 2026-06-17: disclosed: Vulnerability reported by 0sec research team.
  • 2026-07-04: patched: Fix committed to stable kernel trees.
  • 2026-07-19: advisory: CVE-2026-63801 published.

References

Related threats