CVE-2026-64582
Fecha de publicación:
05/08/2026
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
RDMA/rxe: Fix a use-after-free problem in rxe_mmap<br />
<br />
rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list<br />
and releases pending_lock while the struct&#39;s kref is still at 1:<br />
<br />
list_del_init(&ip->pending_mmaps);<br />
spin_unlock_bh(&rxe->pending_lock); /* ref == 1, no lock held */<br />
ret = remap_vmalloc_range(vma, ip->obj, 0); /* walks PTEs */<br />
[...]<br />
rxe_vma_open(vma); /* kref_get, ref → 2 */<br />
remap_vmalloc_range_partial() walks PTEs without any lock.<br />
<br />
A concurrent DESTROY_CQ ioctl on another CPU calls:<br />
<br />
kref_put(&q->ip->ref, rxe_mmap_release) /* ref 1→0 */<br />
vfree(ip->obj) /* clears vmalloc PTEs mid-walk */<br />
kfree(ip) /* frees rxe_mmap_info */<br />
<br />
This yields:<br />
<br />
1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the<br />
per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert<br />
<br />
2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears<br />
it. User VMA holds a PTE to a free&#39;d page which might eventually get<br />
reallocated later by vmalloc which allows the attacker to get a clean<br />
page-level UAF.<br />
<br />
It is worth noting that even though a page-level UAF is possible given<br />
the strong primitive, it is statistically very difficult to achieve<br />
given the very short time window (after the last insert_page and before<br />
the kref_get).<br />
<br />
The call trace are as below:<br />
<br />
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI<br />
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]<br />
CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)<br />
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014<br />
RIP: 0010:validate_page_before_insert+0x32/0x300<br />
Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5<br />
RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202<br />
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000<br />
RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008<br />
RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000<br />
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00<br />
R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20<br />
FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000<br />
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br />
CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0<br />
Call Trace:<br />
<br />
insert_page+0x8f/0x190<br />
? __pfx_insert_page+0x10/0x10<br />
? kasan_save_alloc_info+0x38/0x60<br />
vm_insert_page+0x2e7/0x400<br />
remap_vmalloc_range_partial+0x212/0x3e0<br />
remap_vmalloc_range+0x6e/0xb0<br />
? __kasan_check_write+0x14/0x30<br />
rxe_mmap+0x2e9/0x5d0<br />
ib_uverbs_mmap+0x1ad/0x2c0<br />
__mmap_region+0x12c2/0x2ad0<br />
? __pfx___mmap_region+0x10/0x10<br />
? __sanitizer_cov_trace_switch+0x58/0xb0<br />
? mas_prev_slot+0x360/0x39c0<br />
? __sanitizer_cov_trace_switch+0x58/0xb0<br />
? mas_next_slot+0x1e5b/0x2f40<br />
? __sanitizer_cov_trace_cmp8+0x18/0x30<br />
? unmapped_area_topdown+0x4dd/0x610<br />
? kfree+0x1b1/0x440<br />
? free_cpumask_var+0x16/0x30<br />
? __kasan_slab_free+0x7d/0xa0<br />
? __sanitizer_cov_trace_cmp8+0x18/0x30<br />
mmap_region+0x2e6/0x3c0<br />
do_mmap+0xa3e/0x12a0<br />
? __pfx_do_mmap+0x10/0x10<br />
? __kasan_check_write+0x14/0x30<br />
? down_write_killable+0xba/0x160<br />
? __pfx_down_write_killable+0x10/0x10<br />
? __sanitizer_cov_trace_cmp4+0x16/0x30<br />
vm_mmap_pgoff+0x2d4/0x4a0<br />
? __pfx_vm_mmap_pgoff+0x10/0x10<br />
? fget+0x1bf/0x270<br />
ksys_mmap_pgoff+0x40c/0x690<br />
? __sanitizer_cov_trace_const_cmp4+0x16/0x30<br />
? __pfx_ksys_mmap_pgoff+0x10/0x10<br />
? __kasan_check_write+0x14/0x30<br />
? _raw_spin_trylock+0xbb/0x130<br />
? __pfx__raw_spin_trylock+0x10/0x10<br />
__x64_sys_mmap+0x135/0x1e0<br />
x64_sys_c<br />
---truncated---
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026