{"api_version":"1","generated_at":"2026-08-03T17:27:41+00:00","cve":"CVE-2026-64452","urls":{"html":"https://cve.report/CVE-2026-64452","api":"https://cve.report/api/cve/CVE-2026-64452.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64452","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64452"},"summary":{"title":"6lowpan: fix NHC entry use-after-free on error path","description":"In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix NHC entry use-after-free on error path\n\nlowpan_nhc_do_uncompression() looks up an NHC descriptor while holding\nlowpan_nhc_lock.  If the descriptor has no uncompress callback, the error\npath drops the lock before printing nhc->name.\n\nlowpan_nhc_del() removes descriptors under the same lock and then relies\non synchronize_net() before the owning module can be unloaded.  That only\nwaits for net RX RCU readers.  lowpan_header_decompress() is also exported\nand can be reached from callers that are not necessarily covered by the net\ncore RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive\npath.\n\nThis leaves a race where one task drops lowpan_nhc_lock in the error path,\nanother task unregisters and frees the matching descriptor after\nsynchronize_net() returns, and the first task then dereferences nhc->name\nfor the warning.\n\nWith the post-unlock window widened, KASAN reports:\n\n  BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220\n  Read of size 8\n  lowpan_nhc_do_uncompression\n  lowpan_header_decompress\n\nFix this by printing the warning before dropping lowpan_nhc_lock, so the\ndescriptor name is read while unregister is still excluded.  The malformed\npacket is still rejected with -ENOTSUPP.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-25 10:17:30","updated_at":"2026-07-27 05:16:52"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/9c2f5c0829a8c8b904dae36be6d8056b719ac605","name":"https://git.kernel.org/stable/c/9c2f5c0829a8c8b904dae36be6d8056b719ac605","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a8e3a94711134e898c6021a6b77374efa91b3639","name":"https://git.kernel.org/stable/c/a8e3a94711134e898c6021a6b77374efa91b3639","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cc27aea4d454abfb385ee2c9499c78b96db9b728","name":"https://git.kernel.org/stable/c/cc27aea4d454abfb385ee2c9499c78b96db9b728","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b713aa0cc344f10f7a9928a230b5f5e780d04078","name":"https://git.kernel.org/stable/c/b713aa0cc344f10f7a9928a230b5f5e780d04078","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/1720db928e5a58ca7d75ac1d514c3b73fd7061a7","name":"https://git.kernel.org/stable/c/1720db928e5a58ca7d75ac1d514c3b73fd7061a7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168","name":"https://git.kernel.org/stable/c/593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/80b5c8779acee0550845394fb3e5176a398aa24c","name":"https://git.kernel.org/stable/c/80b5c8779acee0550845394fb3e5176a398aa24c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0beccbcf50de125be5520d0ffc59af4bb8655482","name":"https://git.kernel.org/stable/c/0beccbcf50de125be5520d0ffc59af4bb8655482","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64452","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64452","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 9c2f5c0829a8c8b904dae36be6d8056b719ac605 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 80b5c8779acee0550845394fb3e5176a398aa24c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 cc27aea4d454abfb385ee2c9499c78b96db9b728 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 a8e3a94711134e898c6021a6b77374efa91b3639 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 0beccbcf50de125be5520d0ffc59af4bb8655482 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 b713aa0cc344f10f7a9928a230b5f5e780d04078 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92aa7c65d295f3cbb96904afe335f683e55584b8 1720db928e5a58ca7d75ac1d514c3b73fd7061a7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.96 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.39 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64452","cve":"CVE-2026-64452","epss":"0.002190000","percentile":"0.125020000","score_date":"2026-07-29","updated_at":"2026-07-30 00:09:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/6lowpan/nhc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"9c2f5c0829a8c8b904dae36be6d8056b719ac605","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"80b5c8779acee0550845394fb3e5176a398aa24c","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"cc27aea4d454abfb385ee2c9499c78b96db9b728","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"a8e3a94711134e898c6021a6b77374efa91b3639","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"0beccbcf50de125be5520d0ffc59af4bb8655482","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"b713aa0cc344f10f7a9928a230b5f5e780d04078","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"},{"lessThan":"1720db928e5a58ca7d75ac1d514c3b73fd7061a7","status":"affected","version":"92aa7c65d295f3cbb96904afe335f683e55584b8","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/6lowpan/nhc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.1"},{"lessThan":"4.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.96","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.39","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.96","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.39","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"4.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc1","versionStartIncluding":"4.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix NHC entry use-after-free on error path\n\nlowpan_nhc_do_uncompression() looks up an NHC descriptor while holding\nlowpan_nhc_lock.  If the descriptor has no uncompress callback, the error\npath drops the lock before printing nhc->name.\n\nlowpan_nhc_del() removes descriptors under the same lock and then relies\non synchronize_net() before the owning module can be unloaded.  That only\nwaits for net RX RCU readers.  lowpan_header_decompress() is also exported\nand can be reached from callers that are not necessarily covered by the net\ncore RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive\npath.\n\nThis leaves a race where one task drops lowpan_nhc_lock in the error path,\nanother task unregisters and frees the matching descriptor after\nsynchronize_net() returns, and the first task then dereferences nhc->name\nfor the warning.\n\nWith the post-unlock window widened, KASAN reports:\n\n  BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220\n  Read of size 8\n  lowpan_nhc_do_uncompression\n  lowpan_header_decompress\n\nFix this by printing the warning before dropping lowpan_nhc_lock, so the\ndescriptor name is read while unregister is still excluded.  The malformed\npacket is still rejected with -ENOTSUPP."}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-27T05:01:13.528Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/9c2f5c0829a8c8b904dae36be6d8056b719ac605"},{"url":"https://git.kernel.org/stable/c/80b5c8779acee0550845394fb3e5176a398aa24c"},{"url":"https://git.kernel.org/stable/c/cc27aea4d454abfb385ee2c9499c78b96db9b728"},{"url":"https://git.kernel.org/stable/c/a8e3a94711134e898c6021a6b77374efa91b3639"},{"url":"https://git.kernel.org/stable/c/593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168"},{"url":"https://git.kernel.org/stable/c/0beccbcf50de125be5520d0ffc59af4bb8655482"},{"url":"https://git.kernel.org/stable/c/b713aa0cc344f10f7a9928a230b5f5e780d04078"},{"url":"https://git.kernel.org/stable/c/1720db928e5a58ca7d75ac1d514c3b73fd7061a7"}],"title":"6lowpan: fix NHC entry use-after-free on error path","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64452","datePublished":"2026-07-25T08:51:21.754Z","dateReserved":"2026-07-19T15:36:31.788Z","dateUpdated":"2026-07-27T05:01:13.528Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-25 10:17:30","lastModifiedDate":"2026-07-27 05:16:52","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64452","Ordinal":"1","Title":"6lowpan: fix NHC entry use-after-free on error path","CVE":"CVE-2026-64452","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64452","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix NHC entry use-after-free on error path\n\nlowpan_nhc_do_uncompression() looks up an NHC descriptor while holding\nlowpan_nhc_lock.  If the descriptor has no uncompress callback, the error\npath drops the lock before printing nhc->name.\n\nlowpan_nhc_del() removes descriptors under the same lock and then relies\non synchronize_net() before the owning module can be unloaded.  That only\nwaits for net RX RCU readers.  lowpan_header_decompress() is also exported\nand can be reached from callers that are not necessarily covered by the net\ncore RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive\npath.\n\nThis leaves a race where one task drops lowpan_nhc_lock in the error path,\nanother task unregisters and frees the matching descriptor after\nsynchronize_net() returns, and the first task then dereferences nhc->name\nfor the warning.\n\nWith the post-unlock window widened, KASAN reports:\n\n  BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220\n  Read of size 8\n  lowpan_nhc_do_uncompression\n  lowpan_header_decompress\n\nFix this by printing the warning before dropping lowpan_nhc_lock, so the\ndescriptor name is read while unregister is still excluded.  The malformed\npacket is still rejected with -ENOTSUPP.","Type":"Description","Title":"6lowpan: fix NHC entry use-after-free on error path"}]}}}