Answer in brief
CVE-2026-64543 records a Unknown severity vulnerability in tipc: fix use-after-free of the discoverer in tipc_disc_rcv(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <5e215bf1c47fdddf8203a0fe80a0ed594065f101 || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <ec7d54d8cc1723921d671e3272b427c96366506f || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2 || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <b65289e1c3f352a9f92c6e19713ddd647e033253 || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <1579342d71133da7f00daa02c75cebec7372097b | 5e215bf1c47fdddf8203a0fe80a0ed594065f101, ec7d54d8cc1723921d671e3272b427c96366506f, a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2, b65289e1c3f352a9f92c6e19713ddd647e033253, 1579342d71133da7f00daa02c75cebec7372097b |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(), but tipc_disc_rcv() still dereferences b->disc in RX softirq under rcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv). L2 bearers are safe thanks to the synchronize_net() in tipc_disable_l2_media(), but the UDP bearer defers that call to the cleanup_bearer() workqueue, so the discoverer is freed with no grace period: BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149) Read of size 8 at addr ffff88802348b728 by task poc_tipc/184 <IRQ> tipc_disc_rcv (net/tipc/discover.c:149) tipc_rcv (net/tipc/node.c:2126) tipc_udp_recv (net/tipc/udp_media.c:391) udp_rcv (net/ipv4/udp.c:2643) ip_local_deliver_finish (net/ipv4/ip_input.c:241) </IRQ> Freed by task 181: kfree (mm/slub.c:6565) bearer_disable (net/tipc/bearer.c:418) tipc_nl_bearer_disable (net/tipc/bearer.c:1001) The bearer is freed with kfree_rcu(); free the discoverer the same way. Add an rcu_head to struct tipc_discoverer and free it and its skb from an RCU callback. Because the RCU callback (tipc_disc_free_rcu) lives in module text, a call_rcu() that is still pending when the tipc module is unloaded would invoke a freed function. Add an rcu_barrier() to tipc_exit() after the bearer subsystem has been torn down, so all pending discoverer callbacks have run before the module text goes away. Reachable from an unprivileged user namespace: the TIPCv2 genl family is netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-64543 records a Unknown severity vulnerability in tipc: fix use-after-free of the discoverer in tipc_disc_rcv(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <5e215bf1c47fdddf8203a0fe80a0ed594065f101 || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <ec7d54d8cc1723921d671e3272b427c96366506f || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2 || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <b65289e1c3f352a9f92c6e19713ddd647e033253 || >=25b0b9c4e835ffaa65b61c3efe2e28acf84d0259 <1579342d71133da7f00daa02c75cebec7372097b | 5e215bf1c47fdddf8203a0fe80a0ed594065f101, ec7d54d8cc1723921d671e3272b427c96366506f, a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2, b65289e1c3f352a9f92c6e19713ddd647e033253, 1579342d71133da7f00daa02c75cebec7372097b |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(), but tipc_disc_rcv() still dereferences b->disc in RX softirq under rcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv). L2 bearers are safe thanks to the synchronize_net() in tipc_disable_l2_media(), but the UDP bearer defers that call to the cleanup_bearer() workqueue, so the discoverer is freed with no grace period: BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149) Read of size 8 at addr ffff88802348b728 by task poc_tipc/184 <IRQ> tipc_disc_rcv (net/tipc/discover.c:149) tipc_rcv (net/tipc/node.c:2126) tipc_udp_recv (net/tipc/udp_media.c:391) udp_rcv (net/ipv4/udp.c:2643) ip_local_deliver_finish (net/ipv4/ip_input.c:241) </IRQ> Freed by task 181: kfree (mm/slub.c:6565) bearer_disable (net/tipc/bearer.c:418) tipc_nl_bearer_disable (net/tipc/bearer.c:1001) The bearer is freed with kfree_rcu(); free the discoverer the same way. Add an rcu_head to struct tipc_discoverer and free it and its skb from an RCU callback. Because the RCU callback (tipc_disc_free_rcu) lives in module text, a call_rcu() that is still pending when the tipc module is unloaded would invoke a freed function. Add an rcu_barrier() to tipc_exit() after the bearer subsystem has been torn down, so all pending discoverer callbacks have run before the module text goes away. Reachable from an unprivileged user namespace: the TIPCv2 genl family is netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP.
Quoted source text, attributed separately from HOL analysis.