CVE-2026-74563
CVE CVE-2026-74563EUVD EUVD-2026-59628Veröffentlicht 2026-08-15T12:28:05.000ZZuletzt geändert 2026-08-19T16:39:02.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() rds_tcp_laddr_check() looks up a scoped IPv6 interface with dev_get_by_index_rcu(), drops the RCU read-side lock, and only then passes the bare struct net_device * into ipv6_chk_addr(). dev_get_by_index_rcu() only keeps the device alive within the same RCU read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can free the net_device; ipv6_chk_addr() then dereferences the stale pointer in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading freed memory. Keep the RCU read-side lock held across the ipv6_chk_addr() call instead of dropping it right after the lookup, so the device cannot be freed while it is in use. BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998) Read of size 8 at addr ffff8880106ec000 by task exploit/153 Call Trace: ... kasan_report (mm/kasan/report.c:595) __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998) ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972) rds_tcp_laddr_check (net/rds/tcp.c:370) rds_bind (net/rds/bind.c:248) __sys_bind (net/socket.c:1920) __x64_sys_bind (net/socket.c:1956) do_syscall_64 (arch/x86/entry/syscall_64.c:63) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 6.6.151; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <8398bc477d3cb3e2b018a5aaac2bec0f69acda30; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <78f75d632f74b8de0f081a128588f7c37d0d1164; patch: 7.1.8; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <ba95bce5dfe6e2ef602a87e0557225f2934ccb5c; patch: 6.1.183; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <c4933624a6f416ecfcc31ab58d585da1207a0597; patch: 0; 4.19; patch: 5.15.216; patch: 6.18.44; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff; patch: 6.12.103; patch: 7.2; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <f8a8977af2134a1d91e5f9773cb7d9d53278c830; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <b1d480fce05f857dc438080cd8c9244b84a83494; eee2fa6ab3225192d6d894c54a6fb02ac9efdff6 <76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef; patch: 5.10.265
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.