Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74563

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()<br /> <br /> rds_tcp_laddr_check() looks up a scoped IPv6 interface with<br /> dev_get_by_index_rcu(), drops the RCU read-side lock, and only then<br /> passes the bare struct net_device * into ipv6_chk_addr().<br /> <br /> dev_get_by_index_rcu() only keeps the device alive within the same RCU<br /> read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can<br /> free the net_device; ipv6_chk_addr() then dereferences the stale pointer<br /> in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading<br /> freed memory.<br /> <br /> Keep the RCU read-side lock held across the ipv6_chk_addr() call instead<br /> of dropping it right after the lookup, so the device cannot be freed<br /> while it is in use.<br /> <br /> BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)<br /> Read of size 8 at addr ffff8880106ec000 by task exploit/153<br /> Call Trace:<br /> ...<br /> kasan_report (mm/kasan/report.c:595)<br /> __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)<br /> ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)<br /> rds_tcp_laddr_check (net/rds/tcp.c:370)<br /> rds_bind (net/rds/bind.c:248)<br /> __sys_bind (net/socket.c:1920)<br /> __x64_sys_bind (net/socket.c:1956)<br /> do_syscall_64 (arch/x86/entry/syscall_64.c:63)<br /> entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

Impacto