From mboxrd@z Thu Jan 1 00:00:00 1970 From: AL-KERNEL To: kernel-cve@kernelcve.org Subject: [CVE-2026-64452][MODERATE 7.0] 6lowpan: fix NHC entry use-after-free on error path Date: Sat, 25 Jul 2026 14:23:09 -0400 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-AL-KERNEL-CVE: CVE-2026-64452 X-AL-KERNEL-Priority: MODERATE 7.0 X-AL-KERNEL-Severity: MODERATE 7.0 X-AL-KERNEL-Base-Severity: MODERATE X-AL-KERNEL-KPANIC: NO X-AL-KERNEL-ActionableScore: 5 X-AL-KERNEL-ActionableScore-Lower: 3 X-AL-KERNEL-Commit: 9c2f5c0829a8c8b904dae36be6d8056b719ac605 List-Id: CVE: CVE-2026-64452 Priority: MODERATE 7.0 AL-KERNEL base severity: MODERATE KPANIC flag: NO Patch: 6lowpan: fix NHC entry use-after-free on error path Commit: 9c2f5c0829a8c8b904dae36be6d8056b719ac605 Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9c2f5c0829a8c8b904dae36be6d8056b719ac605 Original CVE announcement: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-64452 Analysis date: Sat, 25 Jul 2026 14:23:09 -0400 ActionableScore: 5 ActionableScore lower bound: 3 Actionable bucket: Actionable Moderate at minimum Manual review required: NO Summary: A race in the 6LoWPAN NHC uncompression error path can dereference a freed NHC descriptor name after unlock, allowing an adjacent network packet plus concurrent unregister timing to trigger a UAF read and potential kernel crash. ====================================================================== ABOUT THIS REPORT ====================================================================== The original Linux kernel CVE announcement for CVE-2026-64452 is available here: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-64452 The original announcement does not normally provide a security severity estimate, CVSS assessment, or enough information to determine whether the reported kernel bug represents a practically relevant security issue. This report was generated by AL-KERNEL, an AI-assisted Linux kernel vulnerability analysis system developed by Alexander Larkin. It combines an autonomous classifier with LLM-assisted technical analysis and a separate ActionableScore mechanism. The purpose of this report is to prioritize Linux kernel CVEs before manual review, identify cases that require prompt investigation, and support automatic closure of issues that are unlikely to have meaningful security impact. Published priority for this report: MODERATE 7.0 Manual review required: NO A detailed explanation of the methodology and priority rules is included at the end of this message. ====================================================================== AL-KERNEL CLASSIFICATION RESULT ====================================================================== CVE-2026-64452 MODERATE CHECK WITH IMPACT FROM ORIG NN LOW Maybe valid. Check manually. Hints by AL-KERNEL: The best (paranoid) CVSS is 'AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H';*CWE-416;CWE-362;CWE-667;Other CVSS 'AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H';BEST CVSS score: '6.4';DESCR 'A race in the 6LoWPAN NHC uncompression error path can leave lowpan_nhc_do_uncompression using an NHC descriptor after lowpan_nhc_lock has been dropped. A malformed adjacent network packet can reach the path through 6LoWPAN receive processing, while concurrent descriptor unregister can free the matching descriptor before nhc name is printed. For the CVSS the PR:N is used because the packet sender does not need a local account or privileges on the target, but AC:H is used because reliable triggering depends on a narrow race with descriptor unregister or module teardown. The issue is adjacent network reachable rather than Internet reachable in typical Bluetooth or IEEE 802.15.4 6LoWPAN deployments. Impact is at least denial of service via kernel crash or KASAN detected use-after-free. For the paranoid score, choose the highest still defensible interpretation supported by the bug class and patch context, with preference for manual-review sensitivity over autoclosed false negatives. The observed primitive is UAF read, so limited confidentiality or integrity impact is kept for review sensitivity, but full privilege escalation is not strongly supported by the diff alone.';YES REQUIRES MANUAL CHECK; ,and ActionableScore result is Actionable Moderate at minimum (with actual score 4) YES READ LOCK RACE ERRORPATH UAF LINUS PACKET INCREASED_TO_MODERATE_FROM_LOW_BASED_ON_GUESSCVSS DECREASED_TO_MODERATEREG_BASED_ON_ACTIONABLESCORELESSTHAN5 NO NO checked ====================================================================== ACTIONABLESCORE ANALYSIS ====================================================================== ActionableScore=5 ActionableScoreLower=3 ## 1. ActionableScore * Conservative score: 3 * Paranoid score: 5 * Final recommended bucket: **Actionable Moderate at minimum** ## 2. Signal breakdown Conservative signals: * Remote reachable / network-triggerable: +2. The malformed packet can reach the 6LoWPAN receive path from an adjacent Bluetooth or IEEE 802.15.4 network peer. * Memory corruption, weak primitive: +1. KASAN reports slab-use-after-free, but the observed stale access is a read of nhc->name for warning output. * Real lifetime corruption: +1. The descriptor can be unregistered and freed after lowpan_nhc_lock is dropped and before nhc->name is dereferenced. * Reliable kernel crash / strong DoS: +1. KASAN reports UAF and non-KASAN kernels may oops or crash depending on allocator state. * Hard or unreliable race / special timing required: -1. Triggering requires overlap between malformed packet processing and NHC descriptor unregister or module teardown. * Rare AND difficult-to-reach subsystem/configuration: -1. 6LoWPAN is not a common Internet-facing path and typically requires Bluetooth 6LoWPAN or IEEE 802.15.4 setup. Paranoid additions: * Confidentiality impact plausible: +1. The stale pointer is read after free, so limited disclosure cannot be fully excluded for triage sensitivity. * Integrity impact plausible: +1. Kept only as a paranoid limited-impact concern due to UAF class, not because the patch shows a write primitive. Race-UAF cap applied: * Conservative score capped at 4 by the race-UAF downgrade rule, actual conservative sum is 3. * Paranoid score capped at 5 by the race-UAF downgrade rule, actual paranoid sum is 5. ## 3. Reachability analysis The packet-side trigger can be initiated by an adjacent network attacker able to send malformed 6LoWPAN traffic to the affected interface. No local account on the target is needed for the packet sender, so the practical PR interpretation is none for the network peer. However, the race also needs concurrent descriptor unregister or module teardown, which is not normally attacker-controlled from the adjacent network alone. Namespaces do not materially improve remote reachability. Local privileges may matter only for the unregister/module side of the race, while the packet side is adjacent-network reachable. The affected path is not a broad default Internet path and depends on 6LoWPAN deployment, for example Bluetooth 6LoWPAN L2CAP or IEEE 802.15.4. Call-site confidence: medium. The commit explicitly names lowpan_header_decompress and the Bluetooth 6LoWPAN L2CAP receive path, but the full caller code is not included in the patch. ## 4. Severity interpretation This is not an ordinary pure DoS cleanup because there is a real slab-use-after-free confirmed by KASAN in a network receive path. At the same time, the demonstrated primitive is a stale read of a descriptor name during warning output, with no shown attacker-controlled reclaim, write-after-free, callback dispatch, type confusion, or refcount takeover. Realistically, it behaves like a race-dependent adjacent-network DoS with weak UAF characteristics. The paranoid score reaches Actionable Moderate because network-adjacent UAF bugs should not be auto-closed without review, but the evidence does not support a Strong Important classification. ## 5. One-sentence report phrase A race in the 6LoWPAN NHC uncompression error path can dereference a freed NHC descriptor name after unlock, allowing an adjacent network packet plus concurrent unregister timing to trigger a UAF read and potential kernel crash. ## 6. Manual review recommendation MANUAL CHECK RECOMMENDED Reason: this is a real race-based UAF in an adjacent network receive path, but the observed primitive is limited to a stale read and does not currently show a strong LPE or arbitrary corruption path. ====================================================================== UPSTREAM PATCH SUMMARY ====================================================================== Patch: 6lowpan: fix NHC entry use-after-free on error path Commit: 9c2f5c0829a8c8b904dae36be6d8056b719ac605 Upstream URL: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9c2f5c0829a8c8b904dae36be6d8056b719ac605 Commit description: lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding lowpan_nhc_lock. If the descriptor has no uncompress callback, the error path drops the lock before printing nhc->name. lowpan_nhc_del() removes descriptors under the same lock and then relies on synchronize_net() before the owning module can be unloaded. That only waits for net RX RCU readers. lowpan_header_decompress() is also exported and can be reached from callers that are not necessarily covered by the net core RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive path. This leaves a race where one task drops lowpan_nhc_lock in the error path, another task unregisters and frees the matching descriptor after synchronize_net() returns, and the first task then dereferences nhc->name for the warning. With the post-unlock window widened, KASAN reports: BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220 Read of size 8 lowpan_nhc_do_uncompression lowpan_header_decompress Fix this by printing the warning before dropping lowpan_nhc_lock, so the descriptor name is read while unregister is still excluded. The malformed packet is still rejected with -ENOTSUPP. Fixes: 92aa7c6 ("6lowpan: add generic nhc layer interface") Cc: stable@vger.kernel.org Reported-by: Yizhou Zhao Reported-by: Yuxiang Yang Reported-by: Ao Wang Reported-by: Xuewei Feng Reported-by: Qi Li Reported-by: Ke Xu Signed-off-by: Yizhou Zhao Acked-by: Alexander Aring Link: https://patch.msgid.link/20260609080054.4541-1-zhaoyz24@mails.tsinghua.edu.cn Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman Changed files: net/6lowpan/nhc.c Diff excerpt: Not included in this email. See the upstream URL for the full patch. Full patch: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9c2f5c0829a8c8b904dae36be6d8056b719ac605 ====================================================================== DETAILED REPORT METHODOLOGY ====================================================================== The original Linux kernel CVE announcement for CVE-2026-64452 can be found here: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-64452 The original CVE announcement normally does not include a security-level estimate. In particular, it may not contain a CVSS assessment, an impact level, or enough information to determine whether the reported bug is a practically relevant security issue. One purpose of this parallel CVE list is to provide that missing technical and prioritization information. The original goal of the AL-KERNEL project was to prioritize Linux kernel CVE analysis automatically before manual review. The system can also help identify non-security issues that may be suitable for automatic closure. This report was generated by AL-KERNEL, an AI-assisted Linux kernel vulnerability analysis system developed by Alexander Larkin. The first analysis stage combines an autonomous classifier with additional LLM-based analysis. The autonomous classifier runs locally on a CPU and is based on a backpropagation neural network. Together, these mechanisms produce a technical vulnerability description, identify likely weakness types, estimate CVSS severity, and provide input for ActionableScore. Two CVSS estimates are retained because incomplete kernel vulnerability information often permits more than one defensible interpretation: Conservative CVSS vector: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H The Best / paranoid CVSS vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H The Best / paranoid CVSS score: 6.4 The conservative vector represents a lower-impact interpretation. The Best/paranoid vector intentionally represents a plausible upper-bound interpretation and should not automatically be treated as demonstrated real-world impact. CVSS may also need to be adjusted for a particular Linux deployment, because actual reachability, privileges, enabled kernel configuration, hardware, namespaces, exposed device nodes, and other environmental conditions can differ significantly between systems. A separate ActionableScore mechanism evaluates practical remediation urgency. Its analysis may include reachability, attack prerequisites, subsystem exposure, memory-corruption characteristics, denial-of-service reliability, and possible confidentiality, integrity, or privilege-escalation impact. Conservative ActionableScore: 3 Paranoid ActionableScore: 5 The final base severity is taken directly from the second tab-separated field of the AL-KERNEL classification result. ActionableScore does not replace or independently override that final AL-KERNEL decision, and if ActionableScore adjusted impact level of ALKERNEL, then you would see self-readable flags above like INCREASED_TO_HIGH_BASED_ON_ACTIONABLESCOREHIGHEREQTHAN7. For an AL-KERNEL result of MODERATE, this report uses the following additional presentation split: ActionableScore below 5 -> MODERATE REGULAR ActionableScore 5 or more -> MODERATE 7.0 The distinction between MODERATE REGULAR and MODERATE 7.0 makes it possible to identify Moderate issues that should receive manual analysis and fixes before lower-priority MODERATE REGULAR issues. In many cases, MODERATE REGULAR fixes may wait for a later rebase or routine update. There is one override in which MODERATE REGULAR becomes MODERATE 7.0 even when the ActionableScore is below 5. When the AL-KERNEL result contains the KPANIC flag, a MODERATE result is always presented as MODERATE 7.0. The KPANIC flag selected with few regexps without usage of AI at all, so it helps to detect cases when Kernel Crash happens and similar (to filter False-Negative results from the LLM usage). KPANIC indicates that a reliable kernel crash, kernel panic, or similarly serious kernel availability impact was identified by the classification workflow. AL-KERNEL base severity for this report: MODERATE KPANIC detected for this report: NO Published priority for this report (same as in Subject): MODERATE 7.0 These results are intended to support engineering triage. They are machine-generated estimates, and cases marked for manual review should be validated by a human security engineer before final disposition. For more info read docs linked from here: https://kernelcve.org/ (and you can submit you own patch there to generate such a report for non-existant CVE-id yet). Note that in many cases this AI tool selects higher severity, than real is (means you can expect Importants instead of Moderate 7.0 or Moderates 7.0 instead of regular Moderates). If you see such cases, please use reply email interface to add additional manual analyses info to this particular CVE. And please, please, let me know when you see Lows instead of Importants or Important instead of Low (because particular for such cases I need to tune this AI tool to make it better for this one and next similar). My contact email for such notifications is alexanjelausa@gmail.com (and both send reply to CVE record itself too and see "reply" button below for howto reply).