Junglewise Threat Intelligence

CVE-2026-64439: Linux Kernel use-after-free in krb5 crypto API

CVE-2026-64439 · Severity: info · CVSS 5.5 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Kerberos 5 (krb5) implementation that could lead to a system crash. The issue occurs when the system uses specific asynchronous encryption hardware, causing the kernel to mistakenly free memory that is still being used by the encryption process. This can result in a 'use-after-free' error, potentially impacting the stability and availability of services using Kerberos, such as AFS or Ceph storage.

Technical details

A use-after-free vulnerability exists in the Linux kernel krb5 implementation within rfc3961_simplified.c and rfc8009_aes2.c. The functions krb5_aead_encrypt() and krb5_aead_decrypt() were designed for synchronous operations and do not provide a completion callback. When an asynchronous AEAD (Authenticated Encryption with Associated Data) provider is used, the functions receive an -EINPROGRESS return code, which they incorrectly treat as a terminal error, leading to the immediate freeing of the data buffer via kfree_sensitive(). However, the asynchronous backend continues to hold a pointer to this buffer, resulting in a dereference of freed memory upon completion. The fix involves forcing the allocation of synchronous AEAD instances by setting the CRYPTO_ALG_ASYNC flag during allocation in krb5_prepare_encryption().

Affected products

  • Linux Linux Kernel 6.15 to 6.18.38, 7.1.3

Timeline

  • 2026-05-10: other: Vulnerability fixed in source code by Michael Bommarito
  • 2026-07-25: disclosed: CVE-2026-64439 published

References

Related threats