Executive brief
The Linux kernel's IEEE 802.15.4 MAC layer (mac802154) beacon worker code contains a use-after-free vulnerability in network device lifecycle management. When a wireless interface is torn down while a beacon transmission worker thread is still running, the worker can continue to access freed memory, potentially causing system crashes or data corruption on devices using IEEE 802.15.4 wireless protocols (such as Zigbee or Thread devices).
Technical details
The vulnerability is a use-after-free in the mac802154_beacon_worker() function. The beacon worker reads a beacon request under RCU protection, derives a sub-interface pointer (sdata), then drops the RCU lock and continues using both sdata and its embedded wpan_dev structure. Meanwhile, mac802154_stop_beacons_locked() can cancel pending work, clear the beacon request, and free the associated memory. A beacon worker already running when interface teardown occurs will dereference the freed netdev private area after the RCU unlock. The fix applies lifetime-management discipline by taking a netdev reference (netdev_hold) while protected by RCU and releasing it (netdev_put) on all code paths that proceed after RCU unlock, preventing the netdev from being freed while the worker is still using it.
Affected products
- Linux Linux kernel all versions with mac802154 beacon support
Timeline
- 2026-08-22: disclosed
- 2026-08-05: patched: upstream fix commit 5f26a690e8efa54315e4922368daf54e0b8f5515