← All Advisories

Linux Kernel rhashtable Walk Restart Leaves a Stale Pointer After a Resize, Causing Use-After-Free in Multi-Fragment Walks

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-64563

Key Details

CVECVE-2026-64563
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-08-19
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

rhashtable: clear stale iter->p on table restart

rhashtable_walk_start_check() has two restart paths when resuming a walk.

When iter->walker.tbl is valid, it re-validates iter->p against the table

and sets iter->p = NULL if the object is gone. When iter->walker.tbl is

NULL (table was freed during resize), it resets slot and skip but forgets

to clear iter->p.

rhashtable_walk_next() then dereferences the stale iter->p, reading

freed memory. This is a use-after-free.

Any caller that does multi-fragment rhashtable walks across

walk_stop/walk_start boundaries is affected. Concrete cases include

netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC

(tipc_nl_sk_walk in net/tipc/socket.c).

Crash stack (netlink_diag):

BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0

Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)

Call Trace:

rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)

__netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)

netlink_diag_dump+0xc2/0x240

netlink_dump+0x5bc/0x1270

netlink_recvmsg+0x7a3/0x980

sock_recvmsg+0x1bc/0x200

__sys_recvfrom+0x1d4/0x2c0 (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-64563
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-64563