CVE-2026-64015: security/keys: fix missed RCU read section on lookup
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026071957-CVE-2026-64015-19c9@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() code really is designed around removing the node from the tree and then freeing it after an RCU grace-period. The regular key handling doesn't see this because holding the keyring semaphore hides any lifetime issues, but the persistent key handling uses a different model. Instead of extending the keyring locking, just do the simple RCU locking that the assoc_array was designed for. The Linux kernel CVE team has assigned CVE-2026-64015 to this issue. Affected and fixed versions =========================== Fixed in 6.1.175 with commit 4c5d407ba3ff7f30561ff73ba1b07ed70c864edc Fixed in 6.6.142 with commit cefa4265b11176c897a7d9e8e54d89e3701c5584 Fixed in 6.12.92 with commit 5659e6923cb72f8e18e8b539109ab512455fe195 Fixed in 6.18.34 with commit 50bb3435a5e627bfbdc52eb4536f49f88b3486b8 Fixed in 7.0.11 with commit 66288dcadf80974436250e9f70ed848836b835b5 Fixed in 7.1 with commit 43a1e3744548e6fd85873e6fb43e293eb4010694 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64015 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: security/keys/keyring.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/4c5d407ba3ff7f30561ff73ba1b07ed70c864edc https://git.kernel.org/stable/c/cefa4265b11176c897a7d9e8e54d89e3701c5584 https://git.kernel.org/stable/c/5659e6923cb72f8e18e8b539109ab512455fe195 https://git.kernel.org/stable/c/50bb3435a5e627bfbdc52eb4536f49f88b3486b8 https://git.kernel.org/stable/c/66288dcadf80974436250e9f70ed848836b835b5 https://git.kernel.org/stable/c/43a1e3744548e6fd85873e6fb43e293eb4010694