CVE-2026-52910
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
19/06/2026
Última modificación:
15/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
bpf: Free reuseport cBPF prog after RCU grace period.<br />
<br />
Eulgyu Kim reported the splat below with a repro. [0]<br />
<br />
The repro sets up a UDP reuseport group with a cBPF prog and<br />
replaces it with a new one while another thread is sending<br />
a UDP packet to the group.<br />
<br />
The reuseport prog is freed by sk_reuseport_prog_free().<br />
bpf_prog_put() is called for "e"BPF prog to destruct through<br />
multiple stages while cBPF prog is freed immediately by<br />
bpf_release_orig_filter() and bpf_prog_free().<br />
<br />
If a reuseport prog is detached from the setsockopt() path<br />
(reuseport_attach_prog() or reuseport_detach_prog()),<br />
sk_reuseport_prog_free() is called without waiting for RCU<br />
readers to complete, resulting in various bugs.<br />
<br />
Let&#39;s defer freeing the reuseport cBPF prog after one RCU<br />
grace period.<br />
<br />
Note "e"BPF prog is safe as is unless the fast path starts<br />
to touch fields destroyed in bpf_prog_put_deferred() and<br />
__bpf_prog_put_noref().<br />
<br />
[0]:<br />
BUG: KASAN: vmalloc-out-of-bounds in reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596<br />
Read of size 4 at addr ffffc9000051e004 by task slowme/10208<br />
CPU: 6 UID: 1000 PID: 10208 Comm: slowme Not tainted 7.0.0-geb7ac95ff75e #32 PREEMPT(full)<br />
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014<br />
Call Trace:<br />
<br />
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120<br />
print_address_description mm/kasan/report.c:378 [inline]<br />
print_report+0xca/0x240 mm/kasan/report.c:482<br />
kasan_report+0x118/0x150 mm/kasan/report.c:595<br />
reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596<br />
udp4_lib_lookup2+0x3bc/0x950 net/ipv4/udp.c:495<br />
__udp4_lib_lookup+0x768/0xe20 net/ipv4/udp.c:723<br />
__udp4_lib_lookup_skb+0x297/0x390 net/ipv4/udp.c:752<br />
__udp4_lib_rcv+0x1312/0x2620 net/ipv4/udp.c:2752<br />
ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207<br />
ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241<br />
NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318<br />
NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318<br />
__netif_receive_skb_one_core net/core/dev.c:6181 [inline]<br />
__netif_receive_skb net/core/dev.c:6294 [inline]<br />
process_backlog+0xaa4/0x1960 net/core/dev.c:6645<br />
__napi_poll+0xae/0x340 net/core/dev.c:7709<br />
napi_poll net/core/dev.c:7772 [inline]<br />
net_rx_action+0x5d7/0xf50 net/core/dev.c:7929<br />
handle_softirqs+0x22b/0x870 kernel/softirq.c:622<br />
do_softirq+0x76/0xd0 kernel/softirq.c:523<br />
<br />
<br />
__local_bh_enable_ip+0xf8/0x130 kernel/softirq.c:450<br />
local_bh_enable include/linux/bottom_half.h:33 [inline]<br />
rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline]<br />
__dev_queue_xmit+0x1dd7/0x3710 net/core/dev.c:4890<br />
neigh_output include/net/neighbour.h:556 [inline]<br />
ip_finish_output2+0xca9/0x1070 net/ipv4/ip_output.c:237<br />
NF_HOOK_COND include/linux/netfilter.h:307 [inline]<br />
ip_output+0x29f/0x450 net/ipv4/ip_output.c:438<br />
ip_send_skb+0x45/0xc0 net/ipv4/ip_output.c:1508<br />
udp_send_skb+0xb04/0x1510 net/ipv4/udp.c:1195<br />
udp_sendmsg+0x1a71/0x2350 net/ipv4/udp.c:1485<br />
sock_sendmsg_nosec net/socket.c:727 [inline]<br />
__sock_sendmsg net/socket.c:742 [inline]<br />
__sys_sendto+0x554/0x680 net/socket.c:2206<br />
__do_sys_sendto net/socket.c:2213 [inline]<br />
__se_sys_sendto net/socket.c:2209 [inline]<br />
__x64_sys_sendto+0xde/0x100 net/socket.c:2209<br />
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]<br />
do_syscall_64+0x160/0xf80 arch/x86/entry/syscall_64.c:94<br />
entry_SYSCALL_64_after_hwframe+0x77/0x7f<br />
RIP: 0033:0x415a2d<br />
Code: b3 66 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48<br />
RSP: 002b:00007f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c<br />
RAX: ffffffffffffffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d<br />
RDX: 0000000000000001 RSI: 00007f6bc31e421f RDI: 0000000000000003<br />
RBP: 00007f6bc31e4240 R08: 00007f6bc31e4220 R09: 0000000000000010<br />
R10: 0000000000000000 R11: <br />
---truncated---
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.5 (incluyendo) | 5.10.259 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.210 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/08264d5bba0bdd3a79bc2984fee09286aba0c4eb
- https://git.kernel.org/stable/c/18fc650ccd7fe3376eca89203668cfb8268f60df
- https://git.kernel.org/stable/c/298db6167f81e9c470a57cf652e4e47757b4293e
- https://git.kernel.org/stable/c/87dfb977bdb6eaa47e9993a34e18f44970f88b1f
- https://git.kernel.org/stable/c/90e47dc5c572d1c73971ac51c7428803f42b78eb
- https://git.kernel.org/stable/c/c3e3fddda6b5d9ba505d218b4055e7d8a282ac57
- https://git.kernel.org/stable/c/f8b8f1d4bb76098e87b8269a0631019648330e6d
- https://git.kernel.org/stable/c/fec41484e7c2aa7ded44c541bba98872be937754
- https://access.redhat.com/security/cve/CVE-2026-52910
- https://bugzilla.redhat.com/show_bug.cgi?id=2490779
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52910.json



