Acknowledged
Created: Dec 8, 2025
Updated: Dec 10, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel
In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]tipc: Fix use-after-free in tipc_mon_reinit_self().[EOL][EOL]syzbot reported use-after-free of tipc_net(net)->monitors[][EOL]in tipc_mon_reinit_self(). [0][EOL][EOL]The array is protected by RTNL, but tipc_mon_reinit_self()[EOL]iterates over it without RTNL.[EOL][EOL]tipc_mon_reinit_self() is called from tipc_net_finalize(),[EOL]which is always under RTNL except for tipc_net_finalize_work().[EOL][EOL]Let's hold RTNL in tipc_net_finalize_work().[EOL][EOL][0]:[EOL]BUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline][EOL]BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162[EOL]Read of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989[EOL][EOL]CPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)}[EOL]Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025[EOL]Workqueue: events tipc_net_finalize_work[EOL]Call Trace:[EOL] <TASK>[EOL] dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120[EOL] print_address_description mm/kasan/report.c:378 [inline][EOL] print_report+0xca/0x240 mm/kasan/report.c:482[EOL] kasan_report+0x118/0x150 mm/kasan/report.c:595[EOL] __kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568[EOL] kasan_check_byte include/linux/kasan.h:399 [inline][EOL] lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842[EOL] __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline][EOL] _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162[EOL] rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline][EOL] rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline][EOL] rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244[EOL] rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243[EOL] write_lock_bh include/linux/rwlock_rt.h:99 [inline][EOL] tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718[EOL] tipc_net_finalize+0x115/0x190 net/tipc/net.c:140[EOL] process_one_work kernel/workqueue.c:3236 [inline][EOL] process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319[EOL] worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400[EOL] kthread+0x70e/0x8a0 kernel/kthread.c:463[EOL] ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148[EOL] ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245[EOL] </TASK>[EOL][EOL]Allocated by task 6089:[EOL] kasan_save_stack mm/kasan/common.c:47 [inline][EOL] kasan_save_track+0x3e/0x80 mm/kasan/common.c:68[EOL] poison_kmalloc_redzone mm/kasan/common.c:388 [inline][EOL] __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405[EOL] kasan_kmalloc include/linux/kasan.h:260 [inline][EOL] __kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407[EOL] kmalloc_noprof include/linux/slab.h:905 [inline][EOL] kzalloc_noprof include/linux/slab.h:1039 [inline][EOL] tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657[EOL] tipc_enable_bearer net/tipc/bearer.c:357 [inline][EOL] __tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047[EOL] __tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline][EOL] tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393[EOL] tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline][EOL] tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321[EOL] genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115[EOL] genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline][EOL] genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210[EOL] netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552[EOL] genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219[EOL] netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline][EOL] netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346[EOL] netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896[EOL] sock_sendmsg_nosec net/socket.c:714 [inline][EOL] __sock_sendmsg+0x21c/0x270 net/socket.c:729[EOL] ____sys_sendmsg+0x508/0x820 net/socket.c:2614[EOL] ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668[EOL] __sys_sendmsg net/socket.c:2700 [inline][EOL] __do_sys_sendmsg net/socket.c:2705 [inline][EOL] __se_sys_sendmsg net/socket.c:2703 [inline][EOL] __x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703[EOL] do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline][EOL] do_syscall_64+0xfa/0x3b0 arch/[EOL]---truncated---