net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
Summary
| CVE | CVE-2026-64188 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-20 17:18:21 UTC |
| Updated | 2026-07-20 17:18:21 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
rmnet_dellink() removes the endpoint from the hash table with
hlist_del_init_rcu() and then immediately frees it with kfree(). However,
RCU readers on the receive path (rmnet_rx_handler ->
__rmnet_map_ingress_handler) may still hold a reference to the endpoint and
dereference ep->egress_dev after the memory has been freed. The endpoint is
a kmalloc-32 object, and the stale read at offset 8 corresponds to the
egress_dev pointer.
BUG: unable to handle page fault for address: ffffffffde942eef
Oops: 0002 [#1] SMP NOPTI
CPU: 1 UID: 0 PID: 137 Comm: poc_write Not tainted 7.0.0+ #4 PREEMPTLAZY
RIP: 0010:rmnet_vnd_rx_fixup (rmnet_vnd.c:27)
Call Trace:
<TASK>
__rmnet_map_ingress_handler (rmnet_handlers.c:48 rmnet_handlers.c:101)
rmnet_rx_handler (rmnet_handlers.c:129 rmnet_handlers.c:235)
__netif_receive_skb_core.constprop.0 (net/core/dev.c:6096)
__netif_receive_skb_one_core (net/core/dev.c:6208)
netif_receive_skb (net/core/dev.c:6467)
tun_get_user (drivers/net/tun.c:1955)
tun_chr_write_iter (drivers/net/tun.c:2003)
vfs_write (fs/read_write.c:688)
ksys_write (fs/read_write.c:740)
</TASK>
Add an rcu_head field to struct rmnet_endpoint and replace kfree() with
kfree_rcu() so the endpoint memory remains valid through the RCU grace
period. Also remove the rmnet_vnd_dellink() call and inline only the
nr_rmnet_devs decrement, since rmnet_vnd_dellink() would set
ep->egress_dev to NULL during the grace period, creating a data race
with lockless readers. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d c4e676c3505c5058922dc1a6f1ded795f6758135 git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d 9918698cf3aee4032e12bb42fd5a951dc465339b git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d 310b93246bfec7d4452507e0c15477377ed9f025 git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d 1078ae8175777e80c9637996fb4a46c55f0ce576 git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d 41e06fcc5df0774d212e70c5b503fc769492bce3 git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d 8b17adf6d4fb6bf61fa4c3f58366a7c082799a71 git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d f193e38cb257d033060b63f1cfd94af076b3a2ab git |
Not specified |
| CNA |
Linux |
Linux |
affected ceed73a2cf4aff2921802aa3d21d45280677547d d00c953a8f69921f484b629801766da68f27f658 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.14 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.14 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.260 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.211 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.177 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.144 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.95 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.37 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.14 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/9918698cf3aee4032e12bb42fd5a951dc465339b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c4e676c3505c5058922dc1a6f1ded795f6758135 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/41e06fcc5df0774d212e70c5b503fc769492bce3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f193e38cb257d033060b63f1cfd94af076b3a2ab |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8b17adf6d4fb6bf61fa4c3f58366a7c082799a71 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/310b93246bfec7d4452507e0c15477377ed9f025 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d00c953a8f69921f484b629801766da68f27f658 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1078ae8175777e80c9637996fb4a46c55f0ce576 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.