Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74583

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/sched: cls_route: fix fastmap use-after-free on filter<br /> <br /> The route4 classifier maintains a 16-slot fastmap cache that stores raw<br /> struct route4_filter pointers indexed by (id, iif). The reader<br /> (route4_classify) populates this cache via route4_set_fastmap() for every<br /> classified packet that hits a filter. The writer (route4_delete,<br /> route4_change) clears the cache via route4_reset_fastmap() before<br /> RCU-deferred kfree of the filter.<br /> <br /> This creates a UAF race:<br /> 1. Reader walks the RCU-protected bucket chain, finds filter f<br /> 2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work()<br /> 3. Reader calls route4_set_fastmap() and writes f into the cache<br /> *after* the writer&amp;#39;s reset, caching a pointer about to be freed<br /> 4. After the RCU grace period, kfree(f) executes<br /> 5. Next classified packet on the same (id, iif) tuple hits the stale<br /> fastmap entry and reads f-&gt;res from freed memory<br /> <br /> Reproduced with an mdelay(100) accelerator in route4_set_fastmap() and a<br /> concurrent add/delete stress test (provided by both zdi and Santosh).<br /> Both triggered KASAN slab-use-after-free reports in the route4 fastmap<br /> paths.<br /> <br /> Fix:<br /> Introduce a per-filter boolean dying flag to suppress stale fastmap<br /> republishing by in-flight readers.

Impacto