CVE-2026-97595
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mac802154: fix use-after-free of sdata via queued RX frames<br />
<br />
The RX softirq producer ieee802154_subif_frame() queues received beacon<br />
and MAC-command frames onto local->rx_beacon_list / rx_mac_cmd_list and<br />
schedules a process-context worker, storing a raw mac_pkt->sdata (and<br />
skb->dev == sdata->dev) with neither a reference nor any locking:<br />
<br />
- the lists have no lock: the softirq producer list_add_tail()s while the<br />
mac_wq worker list_del()s, so sibling interfaces on the same phy corrupt<br />
the list;<br />
<br />
- the workers dereference the interface after it may have been freed.<br />
mac802154_rx_mac_cmd_worker() touches mac_pkt->sdata directly, and<br />
mac802154_rx_beacon_worker() -> mac802154_process_beacon() dereferences<br />
skb->dev (== sdata->dev). Removing an interface frees its sdata<br />
(netdev_priv) while a queued frame still points at it, so a later worker<br />
run is a use-after-free.<br />
<br />
Reproduced under KASAN by flooding a victim interface with MAC command<br />
frames and removing it (the beacon path is the same class via skb->dev):<br />
<br />
BUG: KASAN: slab-use-after-free in mac802154_rx_mac_cmd_worker+0x463/0x630 [mac802154]<br />
Read of size 4 at addr ffff888002f9ea18 by task kworker/u8:1/31<br />
Workqueue: phy0-mac-cmds mac802154_rx_mac_cmd_worker [mac802154]<br />
Call Trace:<br />
mac802154_rx_mac_cmd_worker+0x463/0x630 [mac802154]<br />
process_one_work+0x611/0xe80<br />
worker_thread+0x52e/0xdc0<br />
kthread+0x30c/0x630<br />
ret_from_fork+0x2fd/0x3e0<br />
<br />
Fix both lists together:<br />
<br />
- add local->rx_lock and take it around every list access: the softirq<br />
producer (plain spin_lock, softirq context) and the workers and flush<br />
(spin_lock_bh, process context);<br />
<br />
- pin the interface for the lifetime of a queued frame with<br />
netdev_hold()/netdev_put(), so the worker can safely dereference sdata /<br />
skb->dev even while the interface is being removed;<br />
<br />
- dequeue under the lock at the head and loop-drain the whole list in the<br />
workers (they previously processed one frame per run and relied on a<br />
later enqueue to drain the rest);<br />
<br />
- drop not-yet-started frames of an interface before it is unregistered,<br />
from ieee802154_if_remove() (after the RCU grace period) and from the<br />
ieee802154_remove_interfaces() loop -- the latter is the whole-phy<br />
teardown path, which does not go through ieee802154_if_remove().<br />
<br />
An in-flight worker that already dequeued a frame keeps its own netdev<br />
reference; unregister_netdevice() then waits it out in netdev_run_todo(),<br />
which runs at rtnl_unlock() (rtnl released) and after the interface has<br />
been closed, so it does not pin rtnl. A worker blocked in an association<br />
TX only delays that one interface&#39;s unregister (the usual "waiting for %s<br />
to become free"), it does not hold rtnl. netdev_hold() is used for this<br />
reason instead of a cancel_work_sync() under rtnl, which would block on<br />
the worker&#39;s unbounded MLME TX wait via ieee802154_sync_queue().<br />
<br />
The mac-command worker additionally skips processing for a stopped<br />
interface (ieee802154_sdata_running()), avoiding a needless association<br />
response during teardown.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA


