CVE-2026-74661
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
25/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mac802154: fix netdev use-after-free in beacon worker<br />
<br />
mac802154_beacon_worker() reads local->beacon_req under RCU and derives<br />
the sub-interface from the request, but then drops the RCU read lock and<br />
continues to use both sdata and the embedded wpan_dev.<br />
<br />
mac802154_stop_beacons_locked() cancels only pending beacon work, clears<br />
local->beacon_req and frees the request. A beacon worker that is already<br />
running can therefore continue after interface teardown and dereference<br />
the freed netdev private area.<br />
<br />
The scan worker already pins the netdev before leaving RCU. Apply the<br />
same lifetime rule to the beacon worker: take a netdev reference while<br />
the request is still protected by RCU, and release it on all paths that<br />
continue after the reference is acquired.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/5f26a690e8efa54315e4922368daf54e0b8f5515
- https://git.kernel.org/stable/c/9d067e581597c462c51fee8a30b51bc48a68c4e1
- https://git.kernel.org/stable/c/e5fb0e03bc7f45508c182a427357bf6b389a9033
- https://git.kernel.org/stable/c/e6cd416a899edc912b428c4ba399bd73f516cb31
- https://git.kernel.org/stable/c/fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517



