Junglewise Threat Intelligence

CVE-2026-64543: Linux Kernel TIPC use-after-free in tipc_disc_rcv

CVE-2026-64543 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Transparent Inter-Process Communication (TIPC) protocol. TIPC is used for efficient communication between nodes in a cluster. An unprivileged user could potentially trigger a system crash or instability by disabling certain network interfaces (bearers) while they are still processing data, leading to a 'use-after-free' error.

Technical details

A use-after-free vulnerability exists in net/tipc/discover.c within the tipc_disc_rcv() function. The root cause is that bearer_disable() frees the 'discoverer' structure (b->disc) using a plain kfree() without an RCU grace period, while tipc_disc_rcv() may still be dereferencing it in a softirq context under rcu_read_lock(). This specifically affects UDP bearers because they defer synchronize_net() calls to a workqueue. An attacker in an unprivileged user namespace can trigger this by manipulating TIPCv2 generic netlink commands, which do not require administrative permissions. The fix involves implementing deferred freeing via call_rcu() and adding an rcu_barrier() during module unload.

Affected products

  • Linux Linux Kernel 25b0b9c4e835 to 1579342d7113

Timeline

  • 2026-06-17: patched: Initial fix commit authored
  • 2026-07-27: disclosed: CVE published

References

Related threats