CVE-2026-64452EPSS p11.3%
CVE-2026-64452CVE-2026-64452
linux / linux_kernel
Description
In the Linux kernel, the following vulnerability has been resolved:
6lowpan: fix NHC entry use-after-free on error path
lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding
lowpan_nhc_lock. If the descriptor has no uncompress callback, the error
path drops the lock before printing nhc->name.
lowpan_nhc_del() removes descriptors under the same lock and then relies
on synchronize_net() before the owning module can be unloaded. That only
waits for net RX RCU readers. lowpan_header_decompress() is also exported
and can be reached from callers that are not necessarily covered by the net
core RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive
path.
This leaves a race where one task drops lowpan_nhc_lock in the error path,
another task unregisters and frees the matching descriptor after
synchronize_net() returns, and the first task then dereferences nhc->name
for the warning.
With the post-unlock window widened, KASAN reports:
BUG: KASAN: slab-us
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.22% probability of exploitation · percentile 11.3% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-03 |