Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm rmnet driver, which handles network data for certain mobile hardware. A flaw in how the system removes network endpoints could allow the system to crash or behave unpredictably when a connection is closed while data is still being processed. This could lead to a local denial-of-service (system crash) affecting device stability.
Technical details
A use-after-free (UAF) vulnerability exists in the rmnet_dellink() function within the Qualcomm rmnet driver (drivers/net/ethernet/qualcomm/rmnet). The root cause is that rmnet_dellink() removes an endpoint from the RCU-protected hash table using hlist_del_init_rcu() but immediately calls kfree() without waiting for an RCU grace period. Consequently, concurrent RCU readers in the receive path (rmnet_rx_handler) may attempt to dereference the endpoint's egress_dev pointer after the memory has been reclaimed, leading to a kernel oops/page fault. The fix introduces an rcu_head to the rmnet_endpoint structure and utilizes kfree_rcu() to ensure memory safety during concurrent access.
Affected products
- Linux Linux kernel ceed73a2cf4a to c4e676c3505c
- Linux Linux kernel ceed73a2cf4a to 9918698cf3aee4032e12bb42fd5a951dc465339b
Timeline
- 2026-05-14: other: Patch submitted by developer
- 2026-07-04: patched: Commits merged into stable trees
- 2026-07-20: advisory: CVE published by NVD
References
- https://git.kernel.org/stable/c/1078ae8175777e80c9637996fb4a46c55f0ce576
- https://git.kernel.org/stable/c/310b93246bfec7d4452507e0c15477377ed9f025
- https://git.kernel.org/stable/c/41e06fcc5df0774d212e70c5b503fc769492bce3
- https://git.kernel.org/stable/c/8b17adf6d4fb6bf61fa4c3f58366a7c082799a71
- https://git.kernel.org/stable/c/9918698cf3aee4032e12bb42fd5a951dc465339b
- https://git.kernel.org/stable/c/c4e676c3505c5058922dc1a6f1ded795f6758135
- https://git.kernel.org/stable/c/d00c953a8f69921f484b629801766da68f27f658