From: AL-KERNEL <[email protected]>
To: [email protected]
Subject: [CVE-2026-64452][MODERATE 7.0] 6lowpan: fix NHC entry use-after-free on error path
Date: Sat, 25 Jul 2026 14:23:09 -0400 [thread overview]
Message-ID: <[email protected]> (raw)
CVE: CVE-2026-64452
Priority: MODERATE 7.0
AL-KERNEL base severity: MODERATE
KPANIC flag: NO
Patch: 6lowpan: fix NHC entry use-after-free on error path
Commit: 9c2f5c0829a8c8b904dae36be6d8056b719ac605
Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9c2f5c0829a8c8b904dae36be6d8056b719ac605
Original CVE announcement: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-64452
Analysis date: Sat, 25 Jul 2026 14:23:09 -0400
ActionableScore: 5
ActionableScore lower bound: 3
Actionable bucket: Actionable Moderate at minimum
Manual review required: NO
Summary:
A race in the 6LoWPAN NHC uncompression error path can dereference a freed NHC descriptor name after unlock, allowing an adjacent network packet plus concurrent unregister timing to trigger a UAF read and potential kernel crash.
======================================================================
ABOUT THIS REPORT
======================================================================
The original Linux kernel CVE announcement for CVE-2026-64452 is available here:
https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-64452
The original announcement does not normally provide a security severity
estimate, CVSS assessment, or enough information to determine whether the
reported kernel bug represents a practically relevant security issue.
This report was generated by AL-KERNEL, an AI-assisted Linux kernel
vulnerability analysis system developed by Alexander Larkin. It combines
an autonomous classifier with LLM-assisted technical analysis and a
separate ActionableScore mechanism.
The purpose of this report is to prioritize Linux kernel CVEs before
manual review, identify cases that require prompt investigation, and
support automatic closure of issues that are unlikely to have meaningful
security impact.
Published priority for this report: MODERATE 7.0
Manual review required: NO
A detailed explanation of the methodology and priority rules is included
at the end of this message.
======================================================================
AL-KERNEL CLASSIFICATION RESULT
======================================================================
CVE-2026-64452 MODERATE CHECK WITH IMPACT FROM ORIG NN LOW Maybe valid. Check manually. Hints by AL-KERNEL: The best (paranoid) CVSS is 'AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H';*CWE-416;CWE-362;CWE-667;Other CVSS 'AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H';BEST CVSS score: '6.4';DESCR 'A race in the 6LoWPAN NHC uncompression error path can leave lowpan_nhc_do_uncompression using an NHC descriptor after lowpan_nhc_lock has been dropped. A malformed adjacent network packet can reach the path through 6LoWPAN receive processing, while concurrent descriptor unregister can free the matching descriptor before nhc name is printed. For the CVSS the PR:N is used because the packet sender does not need a local account or privileges on the target, but AC:H is used because reliable triggering depends on a narrow race with descriptor unregister or module teardown. The issue is adjacent network reachable rather than Internet reachable in typical Bluetooth or IEEE 802.15.4 6LoWPAN deployments. Impact is at least denial of service via kernel crash or KASAN detected use-after-free. For the paranoid score, choose the highest still defensible interpretation supported by the bug class and patch context, with preference for manual-review sensitivity over autoclosed false negatives. The observed primitive is UAF read, so limited confidentiality or integrity impact is kept for review sensitivity, but full privilege escalation is not strongly supported by the diff alone.';YES REQUIRES MANUAL CHECK; ,and ActionableScore result is Actionable Moderate at minimum (with actual score 4) YES READ LOCK RACE ERRORPATH UAF LINUS PACKET INCREASED_TO_MODERATE_FROM_LOW_BASED_ON_GUESSCVSS DECREASED_TO_MODERATEREG_BASED_ON_ACTIONABLESCORELESSTHAN5 NO NO checked
======================================================================
ACTIONABLESCORE ANALYSIS
======================================================================
ActionableScore=5
ActionableScoreLower=3
## 1. ActionableScore
* Conservative score: 3
* Paranoid score: 5
* Final recommended bucket: **Actionable Moderate at minimum**
## 2. Signal breakdown
Conservative signals:
* Remote reachable / network-triggerable: +2. The malformed packet can reach the 6LoWPAN receive path from an adjacent Bluetooth or IEEE 802.15.4 network peer.
* Memory corruption, weak primitive: +1. KASAN reports slab-use-after-free, but the observed stale access is a read of nhc->name for warning output.
* Real lifetime corruption: +1. The descriptor can be unregistered and freed after lowpan_nhc_lock is dropped and before nhc->name is dereferenced.
* Reliable kernel crash / strong DoS: +1. KASAN reports UAF and non-KASAN kernels may oops or crash depending on allocator state.
* Hard or unreliable race / special timing required: -1. Triggering requires overlap between malformed packet processing and NHC descriptor unregister or module teardown.
* Rare AND difficult-to-reach subsystem/configuration: -1. 6LoWPAN is not a common Internet-facing path and typically requires Bluetooth 6LoWPAN or IEEE 802.15.4 setup.
Paranoid additions:
* Confidentiality impact plausible: +1. The stale pointer is read after free, so limited disclosure cannot be fully excluded for triage sensitivity.
* Integrity impact plausible: +1. Kept only as a paranoid limited-impact concern due to UAF class, not because the patch shows a write primitive.
Race-UAF cap applied:
* Conservative score capped at 4 by the race-UAF downgrade rule, actual conservative sum is 3.
* Paranoid score capped at 5 by the race-UAF downgrade rule, actual paranoid sum is 5.
## 3. Reachability analysis
The packet-side trigger can be initiated by an adjacent network attacker able to send malformed 6LoWPAN traffic to the affected interface. No local account on the target is needed for the packet sender, so the practical PR interpretation is none for the network peer. However, the race also needs concurrent descriptor unregister or module teardown, which is not normally attacker-controlled from the adjacent network alone.
Namespaces do not materially improve remote reachability. Local privileges may matter only for the unregister/module side of the race, while the packet side is adjacent-network reachable. The affected path is not a broad default Internet path and depends on 6LoWPAN deployment, for example Bluetooth 6LoWPAN L2CAP or IEEE 802.15.4.
Call-site confidence: medium. The commit explicitly names lowpan_header_decompress and the Bluetooth 6LoWPAN L2CAP receive path, but the full caller code is not included in the patch.
## 4. Severity interpretation
This is not an ordinary pure DoS cleanup because there is a real slab-use-after-free confirmed by KASAN in a network receive path. At the same time, the demonstrated primitive is a stale read of a descriptor name during warning output, with no shown attacker-controlled reclaim, write-after-free, callback dispatch, type confusion, or refcount takeover.
Realistically, it behaves like a race-dependent adjacent-network DoS with weak UAF characteristics. The paranoid score reaches Actionable Moderate because network-adjacent UAF bugs should not be auto-closed without review, but the evidence does not support a Strong Important classification.
## 5. One-sentence report phrase
A race in the 6LoWPAN NHC uncompression error path can dereference a freed NHC descriptor name after unlock, allowing an adjacent network packet plus concurrent unregister timing to trigger a UAF read and potential kernel crash.
## 6. Manual review recommendation
MANUAL CHECK RECOMMENDED
Reason: this is a real race-based UAF in an adjacent network receive path, but the observed primitive is limited to a stale read and does not currently show a strong LPE or arbitrary corruption path.
======================================================================
UPSTREAM PATCH SUMMARY
======================================================================
Patch: 6lowpan: fix NHC entry use-after-free on error path
Commit: 9c2f5c0829a8c8b904dae36be6d8056b719ac605
Upstream URL: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9c2f5c0829a8c8b904dae36be6d8056b719ac605
Commit description:
lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding
lowpan_nhc_lock. If the descriptor has no uncompress callback, the error
path drops the lock before printing nhc->name.
lowpan_nhc_del() removes descriptors under the same lock and then relies
on synchronize_net() before the owning module can be unloaded. That only
waits for net RX RCU readers. lowpan_header_decompress() is also exported
and can be reached from callers that are not necessarily covered by the net
core RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive
path.
This leaves a race where one task drops lowpan_nhc_lock in the error path,
another task unregisters and frees the matching descriptor after
synchronize_net() returns, and the first task then dereferences nhc->name
for the warning.
With the post-unlock window widened, KASAN reports:
BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220
Read of size 8
lowpan_nhc_do_uncompression
lowpan_header_decompress
Fix this by printing the warning before dropping lowpan_nhc_lock, so the
descriptor name is read while unregister is still excluded. The malformed
packet is still rejected with -ENOTSUPP.
Fixes: 92aa7c6 ("6lowpan: add generic nhc layer interface")
Cc: [email protected]
Reported-by: Yizhou Zhao <[email protected]>
Reported-by: Yuxiang Yang <[email protected]>
Reported-by: Ao Wang <[email protected]>
Reported-by: Xuewei Feng <[email protected]>
Reported-by: Qi Li <[email protected]>
Reported-by: Ke Xu <[email protected]>
Signed-off-by: Yizhou Zhao <[email protected]>
Acked-by: Alexander Aring <[email protected]>
Link: https://patch.msgid.link/[email protected]
Signed-off-by: Jakub Kicinski <[email protected]>
Signed-off-by: Greg Kroah-Hartman <[email protected]>
Changed files:
net/6lowpan/nhc.c
Diff excerpt:
Not included in this email. See the upstream URL for the full patch.
Full patch:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9c2f5c0829a8c8b904dae36be6d8056b719ac605
======================================================================
DETAILED REPORT METHODOLOGY
======================================================================
The original Linux kernel CVE announcement for CVE-2026-64452 can be found here:
https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-64452
The original CVE announcement normally does not include a security-level
estimate. In particular, it may not contain a CVSS assessment, an impact
level, or enough information to determine whether the reported bug is a
practically relevant security issue. One purpose of this parallel CVE list
is to provide that missing technical and prioritization information.
The original goal of the AL-KERNEL project was to prioritize Linux kernel
CVE analysis automatically before manual review. The system can also help
identify non-security issues that may be suitable for automatic closure.
This report was generated by AL-KERNEL, an AI-assisted Linux kernel
vulnerability analysis system developed by Alexander Larkin.
The first analysis stage combines an autonomous classifier with additional
LLM-based analysis. The autonomous classifier runs locally on a CPU and is
based on a backpropagation neural network. Together, these mechanisms
produce a technical vulnerability description, identify likely weakness
types, estimate CVSS severity, and provide input for ActionableScore.
Two CVSS estimates are retained because incomplete kernel vulnerability
information often permits more than one defensible interpretation:
Conservative CVSS vector: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The Best / paranoid CVSS vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
The Best / paranoid CVSS score: 6.4
The conservative vector represents a lower-impact interpretation.
The Best/paranoid vector intentionally represents a plausible upper-bound
interpretation and should not automatically be treated as demonstrated
real-world impact.
CVSS may also need to be adjusted for a particular Linux deployment,
because actual reachability, privileges, enabled kernel configuration,
hardware, namespaces, exposed device nodes, and other environmental
conditions can differ significantly between systems.
A separate ActionableScore mechanism evaluates practical remediation
urgency. Its analysis may include reachability, attack prerequisites,
subsystem exposure, memory-corruption characteristics, denial-of-service
reliability, and possible confidentiality, integrity, or
privilege-escalation impact.
Conservative ActionableScore: 3
Paranoid ActionableScore: 5
The final base severity is taken directly from the second tab-separated
field of the AL-KERNEL classification result. ActionableScore does not
replace or independently override that final AL-KERNEL decision, and
if ActionableScore adjusted impact level of ALKERNEL, then you would see
self-readable flags above like INCREASED_TO_HIGH_BASED_ON_ACTIONABLESCOREHIGHEREQTHAN7.
For an AL-KERNEL result of MODERATE, this report uses the following
additional presentation split:
ActionableScore below 5 -> MODERATE REGULAR
ActionableScore 5 or more -> MODERATE 7.0
The distinction between MODERATE REGULAR and MODERATE 7.0 makes it
possible to identify Moderate issues that should receive manual analysis
and fixes before lower-priority MODERATE REGULAR issues. In many cases,
MODERATE REGULAR fixes may wait for a later rebase or routine update.
There is one override in which MODERATE REGULAR becomes MODERATE 7.0
even when the ActionableScore is below 5. When the AL-KERNEL result
contains the KPANIC flag, a MODERATE result is always presented as
MODERATE 7.0. The KPANIC flag selected with few regexps without
usage of AI at all, so it helps to detect cases when Kernel Crash happens
and similar (to filter False-Negative results from the LLM usage).
KPANIC indicates that a reliable kernel crash, kernel panic, or similarly
serious kernel availability impact was identified by the classification
workflow.
AL-KERNEL base severity for this report: MODERATE
KPANIC detected for this report: NO
Published priority for this report (same as in Subject): MODERATE 7.0
These results are intended to support engineering triage. They are
machine-generated estimates, and cases marked for manual review should
be validated by a human security engineer before final disposition.
For more info read docs linked from here: https://kernelcve.org/
(and you can submit you own patch there to generate such a report
for non-existant CVE-id yet).
Note that in many cases this AI tool selects higher severity, than
real is (means you can expect Importants instead of Moderate 7.0 or
Moderates 7.0 instead of regular Moderates). If you see such cases,
please use reply email interface to add additional manual analyses
info to this particular CVE.
And please, please, let me know when you see Lows instead of Importants
or Important instead of Low (because particular for such cases I
need to tune this AI tool to make it better for this one and next similar).
My contact email for such notifications is [email protected] (and both
send reply to CVE record itself too and see "reply" button below for howto reply).
reply other threads:[~2026-07-25 18:23 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --from, and --in-reply-to
switches of git-send-email(1) and next cmd tested by kernelcve.org admin:
git send-email --smtp-server=mail.kernelcve.org --smtp-server-port=25 --smtp-auth=none --from='Your Name <youremail@domain.is>' --suppress-cc=all --no-cc \
--in-reply-to=cve-2026-64452.d581474b33e7c7decd9ab2ee@kernelcve.org \
[email protected] \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
The file with msg could look like this then:
cat YOUR_REPLY
Subject: Re: [CVE-2026-64206][MODERATE REGULAR] Bluetooth: L2CAP test
Just testing public-inbox replies.
Thanks,
MyName
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox