CVE-2026-97583
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
afs: Clear stale peer app data after address list changes<br />
<br />
afs_fs_probe_fileserver() fetches the current endpoint state under<br />
server->fs_lock, but leaves old_alist as NULL. Consequently,<br />
afs_set_peer_appdata() treats every address list replacement as initial<br />
setup and only binds the new peers; it never unbinds peers removed from<br />
the old list.<br />
<br />
An address refresh can therefore proceed as follows. CPU 0 replaces<br />
server S&#39;s list and drops Pold without clearing Pold->app_data. The<br />
server destroyer then clears only S&#39;s current peers and lets S reach its<br />
RCU callback. After the callback frees S, CPU 1 handles a callback<br />
through an RxRPC connection that still pins Pold, reads Pold->app_data,<br />
and calls afs_use_server() on the freed object.<br />
<br />
KASAN reported:<br />
<br />
BUG: KASAN: slab-use-after-free in afs_find_server+0x3c/0xa0<br />
Read of size 4 at addr ffff8881013e1af0 by task krxrpcio/7001/74<br />
Call Trace:<br />
afs_find_server+0x3c/0xa0<br />
afs_rx_new_call+0x15c/0x390<br />
rxrpc_new_incoming_call+0x97c/0x1730<br />
rxrpc_input_packet.constprop.0+0xd03/0xec0<br />
rxrpc_io_thread+0x967/0x1640<br />
Allocated by task 93:<br />
afs_lookup_server+0x1a7/0x14c0<br />
afs_alloc_server_list+0x43f/0xb60<br />
afs_create_volume+0x923/0x1490<br />
afs_get_tree+0x1c6/0x10a0<br />
Freed by task 0:<br />
kfree+0x131/0x3c0<br />
rcu_core+0x50a/0x1850<br />
Last potentially related work creation:<br />
__call_rcu_common.constprop.0+0x71/0xa10<br />
afs_put_server+0x213/0x2b0<br />
<br />
Preserve old->addresses for the peer app-data update so that removed<br />
peers are cleared before the endpoint state is replaced. Also advance<br />
both cursors when the old and new lists share a peer; activating the<br />
old/new comparison without this would otherwise loop forever on the<br />
shared entry.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA


