net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

Summary

CVECVE-2026-64188
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-20 17:18:21 UTC
Updated2026-07-20 17:18:21 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() rmnet_dellink() removes the endpoint from the hash table with hlist_del_init_rcu() and then immediately frees it with kfree(). However, RCU readers on the receive path (rmnet_rx_handler -> __rmnet_map_ingress_handler) may still hold a reference to the endpoint and dereference ep->egress_dev after the memory has been freed. The endpoint is a kmalloc-32 object, and the stale read at offset 8 corresponds to the egress_dev pointer. BUG: unable to handle page fault for address: ffffffffde942eef Oops: 0002 [#1] SMP NOPTI CPU: 1 UID: 0 PID: 137 Comm: poc_write Not tainted 7.0.0+ #4 PREEMPTLAZY RIP: 0010:rmnet_vnd_rx_fixup (rmnet_vnd.c:27) Call Trace: <TASK> __rmnet_map_ingress_handler (rmnet_handlers.c:48 rmnet_handlers.c:101) rmnet_rx_handler (rmnet_handlers.c:129 rmnet_handlers.c:235) __netif_receive_skb_core.constprop.0 (net/core/dev.c:6096) __netif_receive_skb_one_core (net/core/dev.c:6208) netif_receive_skb (net/core/dev.c:6467) tun_get_user (drivers/net/tun.c:1955) tun_chr_write_iter (drivers/net/tun.c:2003) vfs_write (fs/read_write.c:688) ksys_write (fs/read_write.c:740) </TASK> Add an rcu_head field to struct rmnet_endpoint and replace kfree() with kfree_rcu() so the endpoint memory remains valid through the RCU grace period. Also remove the rmnet_vnd_dellink() call and inline only the nr_rmnet_devs decrement, since rmnet_vnd_dellink() would set ep->egress_dev to NULL during the grace period, creating a data race with lockless readers.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d c4e676c3505c5058922dc1a6f1ded795f6758135 git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d 9918698cf3aee4032e12bb42fd5a951dc465339b git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d 310b93246bfec7d4452507e0c15477377ed9f025 git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d 1078ae8175777e80c9637996fb4a46c55f0ce576 git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d 41e06fcc5df0774d212e70c5b503fc769492bce3 git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d 8b17adf6d4fb6bf61fa4c3f58366a7c082799a71 git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d f193e38cb257d033060b63f1cfd94af076b3a2ab git Not specified
CNA Linux Linux affected ceed73a2cf4aff2921802aa3d21d45280677547d d00c953a8f69921f484b629801766da68f27f658 git Not specified
CNA Linux Linux affected 4.14 Not specified
CNA Linux Linux unaffected 4.14 semver Not specified
CNA Linux Linux unaffected 5.10.260 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.211 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.177 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.144 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.95 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.37 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.14 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/9918698cf3aee4032e12bb42fd5a951dc465339b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c4e676c3505c5058922dc1a6f1ded795f6758135 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/41e06fcc5df0774d212e70c5b503fc769492bce3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f193e38cb257d033060b63f1cfd94af076b3a2ab 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8b17adf6d4fb6bf61fa4c3f58366a7c082799a71 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/310b93246bfec7d4452507e0c15477377ed9f025 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d00c953a8f69921f484b629801766da68f27f658 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1078ae8175777e80c9637996fb4a46c55f0ce576 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report