Executive brief
A vulnerability was identified in the Linux kernel's Transparent Inter-Process Communication (TIPC) protocol. TIPC is used for efficient communication between nodes in a cluster. An unprivileged user could potentially trigger a system crash or instability by disabling certain network interfaces (bearers) while they are still processing data, leading to a 'use-after-free' error.
Technical details
A use-after-free vulnerability exists in net/tipc/discover.c within the tipc_disc_rcv() function. The root cause is that bearer_disable() frees the 'discoverer' structure (b->disc) using a plain kfree() without an RCU grace period, while tipc_disc_rcv() may still be dereferencing it in a softirq context under rcu_read_lock(). This specifically affects UDP bearers because they defer synchronize_net() calls to a workqueue. An attacker in an unprivileged user namespace can trigger this by manipulating TIPCv2 generic netlink commands, which do not require administrative permissions. The fix involves implementing deferred freeing via call_rcu() and adding an rcu_barrier() during module unload.
Affected products
- Linux Linux Kernel 25b0b9c4e835 to 1579342d7113
Timeline
- 2026-06-17: patched: Initial fix commit authored
- 2026-07-27: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b
- https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101
- https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2
- https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253
- https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f