keys: Fix linking a duplicate key to a keyring's assoc_array
In the Linux kernel, the following vulnerability has been resolved: keys: Fix linking a duplicate key to a keyring's assoc_array When making a DNS query inside the kernel using dns_query(), the request code can in rare cases end up creating a duplicate index key in the assoc_array of the destination keyring. It is eventually found by a BUG_ON() check in the assoc_array implementation and results in a crash. Example report: [2158499.700025] kernel BUG at ../lib/assoc_array.c:652! [2158499.700039] invalid opcode: 0000 [#1] SMP PTI [2158499.700065] CPU: 3 PID: 31985 Comm: kworker/3:1 Kdump: loaded Not tainted 5.3.18-150300.59.90-default #1 SLE15-SP3 [2158499.700096] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 [2158499.700351] Workqueue: cifsiod cifs_resolve_server [cifs] [2158499.700380] RIP: 0010:assoc_array_insert+0x85f/0xa40 [2158499.700401] Code: ff 74 2b 48 8b 3b 49 8b 45 18 4c 89 e6 48 83 e7 fe e8 95 ec 74 00 3b 45 88 7d db 85 c0 79 d4 0f 0b 0f 0b 0f 0b e8 41 f2 be ff <0f> 0b 0f 0b 81 7d 88 ff ff ff 7f 4c 89 eb 4c 8b ad 58 ff ff ff 0f [2158499.700448] RSP: 0018:ffffc0bd6187faf0 EFLAGS: 00010282 [2158499.700470] RAX: ffff9f1ea7da2fe8 RBX: ffff9f1ea7da2fc1 RCX: 0000000000000005 [2158499.700492] RDX: 0000000000000000 RSI: 0000000000000005 RDI: 0000000000000000 [2158499.700515] RBP: ffffc0bd6187fbb0 R08: ffff9f185faf1100 R09: 0000000000000000 [2158499.700538] R10: ffff9f1ea7da2cc0 R11: 000000005ed8cec8 R12: ffffc0bd6187fc28 [2158499.700561] R13: ffff9f15feb8d000 R14: ffff9f1ea7da2fc0 R15: ffff9f168dc0d740 [2158499.700585] FS: 0000000000000000(0000) GS:ffff9f185fac0000(0000) knlGS:0000000000000000 [2158499.700610] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [2158499.700630] CR2: 00007fdd94fca238 CR3: 0000000809d8c006 CR4: 00000000003706e0 [2158499.700702] Call Trace: [2158499.700741] ? key_alloc+0x447/0x4b0 [2158499.700768] ? __key_link_begin+0x43/0xa0 [2158499.700790] __key_link_begin+0x43/0xa0 [2158499.700814] request_key_and_link+0x2c7/0x730 [2158499.700847] ? dns_resolver_read+0x20/0x20 [dns_resolver] [2158499.700873] ? key_default_cmp+0x20/0x20 [2158499.700898] request_key_tag+0x43/0xa0 [2158499.700926] dns_query+0x114/0x2ca [dns_resolver] [2158499.701127] dns_resolve_server_name_to_ip+0x194/0x310 [cifs] [2158499.701164] ? scnprintf+0x49/0x90 [2158499.701190] ? __switch_to_asm+0x40/0x70 [2158499.701211] ? __switch_to_asm+0x34/0x70 [2158499.701405] reconn_set_ipaddr_from_hostname+0x81/0x2a0 [cifs] [2158499.701603] cifs_resolve_server+0x4b/0xd0 [cifs] [2158499.701632] process_one_work+0x1f8/0x3e0 [2158499.701658] worker_thread+0x2d/0x3f0 [2158499.701682] ? process_one_work+0x3e0/0x3e0 [2158499.701703] kthread+0x10d/0x130 [2158499.701723] ? kthread_park+0xb0/0xb0 [2158499.701746] ret_from_fork+0x1f/0x40 The situation occurs as follows: * Some kernel facility invokes dns_query() to resolve a hostname, for example, "abcdef". The function registers its global DNS resolver cache as current->cred.thread_keyring and passes the query to request_key_net() -> request_key_tag() -> request_key_and_link(). * Function request_key_and_link() creates a keyring_search_context object. Its match_data.cmp method gets set via a call to type->match_preparse() (resolves to dns_resolver_match_preparse()) to dns_resolver_cmp(). * Function request_key_and_link() continues and invokes search_process_keyrings_rcu() which returns that a given key was not found. The control is then passed to request_key_and_link() -> construct_alloc_key(). * Concurrently to that, a second task similarly makes a DNS query for "abcdef." and its result gets inserted into the DNS resolver cache. * Back on the first task, function construct_alloc_key() first runs __key_link_begin() to determine an assoc_array_edit operation to insert a new key. Index keys in the array are compared exactly as-is, using keyring_compare_object(). The operation ---truncated---
- Yayın
- 30 Ara 2025
- Güncelleme
- 17 Haz 2026
- EPSS
- %0,2 · 9. yüzdelik
- CWE
- —
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
0
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,2
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinEtkilenen sistemler
—
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 5.3etkilenir
- df593ee23e05cdda16c8c995e5818779431bb29f ve sonrası · 65bd66a794bfa059375ec834885bb610d75c0182 öncesietkilenir · git
- df593ee23e05cdda16c8c995e5818779431bb29f ve sonrası · 0a6b0ca58685be34979236f83f2b322635b80b32 öncesietkilenir · git
- df593ee23e05cdda16c8c995e5818779431bb29f ve sonrası · 9aecfebea24fe6071ace5cc9fd6d690b87276bbb öncesietkilenir · git
- df593ee23e05cdda16c8c995e5818779431bb29f ve sonrası · 00edfa6d4fe022942e2f2e6f3294ff13ef78b15c öncesietkilenir · git
- df593ee23e05cdda16c8c995e5818779431bb29f ve sonrası · e091bb55af9a930801f83df78195a908a76e1479 öncesietkilenir · git
- df593ee23e05cdda16c8c995e5818779431bb29f ve sonrası · d55901522f96082a43b9842d34867363c0cdbac5 öncesietkilenir · git
- 5.3 öncesietkilenmez · semver
- 5.4.253 ve sonrası · 5.4.* dahil öncesietkilenmez · semver
- 5.10.188 ve sonrası · 5.10.* dahil öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.52-1 öncesi | 6.1.52-1 |
| Debian:13 | linux | 6.4.11-1 öncesi | 6.4.11-1 |
| Red Hat:enterprise_linux:9::appstream | bpftool-debuginfo | 0:7.2.0-362.13.1.el9_3 öncesi | 0:7.2.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-64k-debug-debuginfo | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-64k-debug-devel | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-64k-debug-devel-matched | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-64k-debuginfo | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-64k-devel | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-64k-devel-matched | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debug-debuginfo | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debug-devel | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debug-devel-matched | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debuginfo | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debuginfo-common-aarch64 | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debuginfo-common-ppc64le | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debuginfo-common-s390x | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-debuginfo-common-x86_64 | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-devel | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-devel-matched | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-doc | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-tools-debuginfo | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-zfcpdump-debuginfo | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-zfcpdump-devel | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
| Red Hat:enterprise_linux:9::appstream | kernel-zfcpdump-devel-matched | 0:5.14.0-362.13.1.el9_3 öncesi | 0:5.14.0-362.13.1.el9_3 |
+56
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Planlayın
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Planlayın
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Planlayın
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Planlayın
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Planlayın
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Planlayın
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 00edfa6d4fe022942e2f2e6f3294ff13ef78b15c | Üretici (CNA) |
| Linux Linux | 0a6b0ca58685be34979236f83f2b322635b80b32 | Üretici (CNA) |
| Linux Linux | 65bd66a794bfa059375ec834885bb610d75c0182 | Üretici (CNA) |
| Linux Linux | 9aecfebea24fe6071ace5cc9fd6d690b87276bbb | Üretici (CNA) |
| Linux Linux | d55901522f96082a43b9842d34867363c0cdbac5 | Üretici (CNA) |
| Linux Linux | e091bb55af9a930801f83df78195a908a76e1479 | Üretici (CNA) |
| debian:linux | 6.1.52-1 · Debian:12 | Paket deposu (OSV) |
| red hat:bpftool-debuginfo | 0:7.2.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debug-debuginfo | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debug-devel | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debug-devel-matched | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-debuginfo | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-devel | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-64k-devel-matched | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debug-debuginfo | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debug-devel | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debug-devel-matched | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debuginfo | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:kernel-debuginfo-common-aarch64 | 0:5.14.0-362.13.1.el9_3 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Bu kayıt için CVSS vektörü yok; saldırı koşulları çıkarılamıyor.
Zayıflık sınıfı (CWE)
—
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Değişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/00edfa6d4fe022942e2f2e6f3294ff13ef78b15c
- git.kernel.org/stable/c/0a6b0ca58685be34979236f83f2b322635b80b32
- git.kernel.org/stable/c/65bd66a794bfa059375ec834885bb610d75c0182
- git.kernel.org/stable/c/9aecfebea24fe6071ace5cc9fd6d690b87276bbb
- git.kernel.org/stable/c/d55901522f96082a43b9842d34867363c0cdbac5
- git.kernel.org/stable/c/e091bb55af9a930801f83df78195a908a76e1479
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.