Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97595

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> mac802154: fix use-after-free of sdata via queued RX frames<br /> <br /> The RX softirq producer ieee802154_subif_frame() queues received beacon<br /> and MAC-command frames onto local-&gt;rx_beacon_list / rx_mac_cmd_list and<br /> schedules a process-context worker, storing a raw mac_pkt-&gt;sdata (and<br /> skb-&gt;dev == sdata-&gt;dev) with neither a reference nor any locking:<br /> <br /> - the lists have no lock: the softirq producer list_add_tail()s while the<br /> mac_wq worker list_del()s, so sibling interfaces on the same phy corrupt<br /> the list;<br /> <br /> - the workers dereference the interface after it may have been freed.<br /> mac802154_rx_mac_cmd_worker() touches mac_pkt-&gt;sdata directly, and<br /> mac802154_rx_beacon_worker() -&gt; mac802154_process_beacon() dereferences<br /> skb-&gt;dev (== sdata-&gt;dev). Removing an interface frees its sdata<br /> (netdev_priv) while a queued frame still points at it, so a later worker<br /> run is a use-after-free.<br /> <br /> Reproduced under KASAN by flooding a victim interface with MAC command<br /> frames and removing it (the beacon path is the same class via skb-&gt;dev):<br /> <br /> BUG: KASAN: slab-use-after-free in mac802154_rx_mac_cmd_worker+0x463/0x630 [mac802154]<br /> Read of size 4 at addr ffff888002f9ea18 by task kworker/u8:1/31<br /> Workqueue: phy0-mac-cmds mac802154_rx_mac_cmd_worker [mac802154]<br /> Call Trace:<br /> mac802154_rx_mac_cmd_worker+0x463/0x630 [mac802154]<br /> process_one_work+0x611/0xe80<br /> worker_thread+0x52e/0xdc0<br /> kthread+0x30c/0x630<br /> ret_from_fork+0x2fd/0x3e0<br /> <br /> Fix both lists together:<br /> <br /> - add local-&gt;rx_lock and take it around every list access: the softirq<br /> producer (plain spin_lock, softirq context) and the workers and flush<br /> (spin_lock_bh, process context);<br /> <br /> - pin the interface for the lifetime of a queued frame with<br /> netdev_hold()/netdev_put(), so the worker can safely dereference sdata /<br /> skb-&gt;dev even while the interface is being removed;<br /> <br /> - dequeue under the lock at the head and loop-drain the whole list in the<br /> workers (they previously processed one frame per run and relied on a<br /> later enqueue to drain the rest);<br /> <br /> - drop not-yet-started frames of an interface before it is unregistered,<br /> from ieee802154_if_remove() (after the RCU grace period) and from the<br /> ieee802154_remove_interfaces() loop -- the latter is the whole-phy<br /> teardown path, which does not go through ieee802154_if_remove().<br /> <br /> An in-flight worker that already dequeued a frame keeps its own netdev<br /> reference; unregister_netdevice() then waits it out in netdev_run_todo(),<br /> which runs at rtnl_unlock() (rtnl released) and after the interface has<br /> been closed, so it does not pin rtnl. A worker blocked in an association<br /> TX only delays that one interface&amp;#39;s unregister (the usual "waiting for %s<br /> to become free"), it does not hold rtnl. netdev_hold() is used for this<br /> reason instead of a cancel_work_sync() under rtnl, which would block on<br /> the worker&amp;#39;s unbounded MLME TX wait via ieee802154_sync_queue().<br /> <br /> The mac-command worker additionally skips processing for a stopped<br /> interface (ieee802154_sdata_running()), avoiding a needless association<br /> response during teardown.