Executive brief
The Linux kernel's RDS (Reliable Datagram Sockets) TCP component has a memory safety bug in IPv6 address validation. An attacker with local access can trigger a use-after-free condition by binding to an IPv6 address while concurrently deleting network interfaces, causing the kernel to read freed memory and potentially crash the system or execute arbitrary code.
Technical details
The vulnerability is a use-after-free (CWE-416) in the rds_tcp_laddr_check() function in net/rds/tcp.c. The function acquires a network device reference via dev_get_by_index_rcu() under RCU protection, but then releases the RCU read lock before passing the device pointer to ipv6_chk_addr(). A concurrent RTM_DELLINK operation can free the network device while ipv6_chk_addr() is dereferencing it, leading to KASAN-detectable freed memory access. Attack vector requires local network access and is triggered through the bind() syscall. The fix involves holding the RCU read-side lock across the entire ipv6_chk_addr() call to ensure the device remains valid during its use. Patches are available in Linux kernel stable trees.
Affected products
- Linux Linux kernel Multiple versions (vulnerable from introduction of RDS IPv6 support; fixed in stable branches 5.4, 5.10, 5.15, 6.1, 6.6 and later)
Timeline
- 2026-07-22: disclosed
- 2026-07-23: patched
- 2026-08-15: advisory