No kernel Linux, a seguinte vulnerabilidade foi resolvida. ipv 4: fib: Não descarregue o fib_info em fib_ fol_ notify(). syzbot relatou o uso-após-livre no nsim_fib 4 _prepare_evento(). [ 0 ]. O problema é que as seguintes funções chamam fib_info_hold() / refcount_inc() enquanto jogam o fib_info em RCU, o que é inseguro.
* mlxsw_sp_router_fib 4 _event() * rocker_router_fib_event() * nsim_fib 4 _prepare_evento(). refcount_inc_ not_zero() deve ser usado, mas seria tarde demais. Vamos garantir a vida útil do fib_info no fib_leaf_notify().
Note que IPv 6 não necessita da mudança correspondente desde o fib 6 _table_dump() mantém fib 6 _table.tb 6 _Locação. [ 0 ]: refcount_t: adição no 0; use- depois- livre. ATENÇÃO: lib/ refcount.c: 25 na refcount_warn_saturate+ 0 x 9 f/ 0 x 110 lib/ refcount.c: 25, CPU# 0: kworker/u 8: 15 / 3420 Módulos conectados em: CPU: 0 UID: 0 PID: 3420 Comunicação: kworker/u 8: 15 Não está contaminado o syzkaller # 0 PREEMPT_{RT, (full)} Nome do hardware: Google Google Calcular Motor/Google Calcular Motor, BIOS Google 04 / 18 / 2026 Reprodução: netns cleanup_ net RIP: 0010:refcount_warn_saturate+ 0 x 9 f/ 0 x 110 lib/ refcount.c: 25 Código: eb 66 85 db 74 3 e 83 fb 01 75 4 c e 8 1 b f 1 22 fd 48 8 d 3 d 84 cb f 1 0 a 67 48 0 f b 9 3 a eb 4 a e 8 08 f 1 22 fd 48 8 d 3 d 81 cb f 1 0 a 48 0 f b 9 3 a eb 37 e 8 f 5 f 0 22 fd 48 8 d 3 d 7 e cb f 1 0 a 67 48 0 f RSP: 0018:ffffc 9000 f 2 c 7270 EFLAGS: 00010293 RAX: ffffffffff 84 a 18858 RBX: 0000000000000002 RCX: ffff 888032 ff 9 ec 0 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff 8 f 9353 e 0 RBP: 0000000000000000 R 08: ffff 888032 ff 9 ec 0 R 09: 0000000000000005 R 10: 0000000000000100 R 11: 0000000000000004 R 12: ffff 8880570 cc 000 R 13: dffffc 0000000000 R 14: ffff 88802 b 40563 c R 15: ffff 8880570 cc 000 FS: 0000000000000000 ( 0000 ) GS:ffff 888126173000 ( 0000 ) knIGS: 0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR 0: 0000000080050033 CR 2: 00007 fb 1 f 4 d 5 d 000 CR 3: 000000006072 a 000 CR 4: 00000000003526 f 0 Chame o rastreamento: __refcount_ add include/linux/refcount.h:- 1 [inline] __ refcount_ inc include/linux/ refcount.h: 366 [inline] refcount_ inc include/linux/refcount.h: 383 [inline] fib_info_hold include/net/ip_fib.h: 629 [inline] nsim_fib 4 _prepare_evento drivers/net/netdevsim/fib.c: 930 [inline] nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c: 1000 [inline] nsim_fib_event_nb+ 0 x 1055 / 0 x 1240 drivers/net/netdevsim/fib.c: 1043 call_fib_notifier+ 0 x 45 / 0 x 80 líquido/core/fib_notifier.c: 25 net/ipv do nome de nome de arquivo 4 /fib_trie.c: 90 [inline] fib_leaf_notifique net/ipv 4 /fib_trie.c: 2176 [inline] fib_table_notificar rede/ipv 4 /fib_trie.c: 2194 [inline] fib_notifier+ 0 x 36 b/ 0 x 5 e 0 rede/ipv 4 /fib_trie.c: 2217 Fib_net_dump net/core/fib_notifier.c: 70 [inline] register_fib_notifier+ 0 x 184 / 0 x 360 líquido/core/fib_notifier.c: 108 nsim_fib_criar+ 0 x 85 d/ 0 x 9 f 0 drivers/net/netdevsim/fib.c: 1596 nsim_dev_reload_crear drivers/net/netdevsim/dev.c: 1604 [inline] nsim_dev_reload_up+ 0 x 374 / 0 x 7 c 0 drivers/net/netdevsim/dev.c: 1058 devlink_recarregar+ 0 x 501 / 0 x 8 d 0 net/ devlink/ dev.c: 475 devlink_pernet_pre_exit+ 0 x 1 ff/ 0 x 420 net/ devlink/core.c: 558 ops_pre_exit_list net/core/net_namespace.c: 161 [inline] ops_undo_list+ 0 x 187 / 0 x 940 net/core/net_namespace.c: 234 Limpeza_net+ 0 x 56 e/ 0 x 800 net/core/net_namespace.c: 702 process_one_work kernel/workqueue.c: 3314 [inline] processo_programado_funciona+ 0 xb 5 d/ 0 x 1860 kernel/workqueue.c: 3397 worker_thread+ 0 xa 53 / 0 xfc 0 kernel/workqueue.c: 3478 kthread+ 0 x 388 / 0 x 470 kernel/ kthread.c: 436 ret_from_fork+ 0 x 514 / 0 xb 70 arch/ x 86 /kernel/ process.c: 158 ret_from_fork_asm+ 0 x 1 a/ 0 x 30 arch/ x 86 /entrada/entrada_ 64.S: 245.
Registro de aconselhamento: GHSA-xcp 6 - fchg- 2 cm 7. Identificadores relacionados: CVE- 2026 - 74289.
Tempo: GitHub Advisory Database publicou este registro em 2026 - 08 - 15 T 06: 32: 28.000 Z e lista a sua última modificação como 2026 - 08 - 17 T 06: 33: 36.000 Z.
Severidade: ALTAMENTE. Dados de pontuação publicados: CVSS_V 3: CVSS: 3.1 /AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Software afetado: o registro de aconselhamento não fornece um pacote normalizado ou faixa de versões.
Classificação e evidência: nenhum identificador CWE está listado. O registro contém 3 suporte de referências nestes tipos: AVISO, WEB.