<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 15:42:46 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-26737 — bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-26737</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel&lt;/p&gt;
&lt;p&gt;The following race is possible between bpf_timer_cancel_and_free
and bpf_timer_cancel. It will lead a UAF on the timer-&amp;gt;timer.&lt;/p&gt;
&lt;p&gt;bpf_timer_cancel();
	spin_lock();
	t = timer-&amp;gt;time;
	spin_unlock();&lt;/p&gt;
&lt;p&gt;bpf_timer_cancel_and_free();
						spin_lock();
						t = timer-&amp;gt;timer;
						timer-&amp;gt;timer = NULL;
						spin_unlock();
						hrtimer_cancel(&amp;amp;t-&amp;gt;timer);
						kfree(t);&lt;/p&gt;
&lt;p&gt;/* UAF on t */
	hrtimer_cancel(&amp;amp;t-&amp;gt;timer);&lt;/p&gt;
&lt;p&gt;In bpf_timer_cancel_and_free, this patch frees the timer-&amp;gt;timer
after a rcu grace period. This requires a rcu_head addition
to the &amp;#34;struct bpf_hrtimer&amp;#34;. Another kfree(t) happens in bpf_timer_init,
this does not need a kfree_rcu because it is still under the
spin_lock and timer-&amp;gt;timer has not been visible by others yet.&lt;/p&gt;
&lt;p&gt;In bpf_timer_cancel, rcu_read_lock() is added because this helper
can be used in a non rcu critical section context (e.g. from
a sleepable bpf prog). Other timer-&amp;gt;timer usages in helpers.c
have been audited, bpf_timer_cancel() is the only place where
timer-&amp;gt;timer is used outside of the spin_lock.&lt;/p&gt;
&lt;p&gt;Another solution considered is to mark a t-&amp;gt;flag in bpf_timer_cancel
and clear it after hrtimer_cancel() is done.  In bpf_timer_cancel_and_free,
it busy waits for the flag to be cleared before kfree(t). This patch
goes with a straight forward solution and frees timer-&amp;gt;timer after
a rcu grace period.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel&lt;/p&gt;
&lt;p&gt;The following race is possible between bpf_timer_cancel_and_free
and bpf_timer_cancel. It will lead a UAF on the timer-&amp;gt;timer.&lt;/p&gt;
&lt;p&gt;bpf_timer_cancel();
	spin_lock();
	t = timer-&amp;gt;time;
	spin_unlock();&lt;/p&gt;
&lt;p&gt;bpf_timer_cancel_and_free();
						spin_lock();
						t = timer-&amp;gt;timer;
						timer-&amp;gt;timer = NULL;
						spin_unlock();
						hrtimer_cancel(&amp;amp;t-&amp;gt;timer);
						kfree(t);&lt;/p&gt;
&lt;p&gt;/* UAF on t */
	hrtimer_cancel(&amp;amp;t-&amp;gt;timer);&lt;/p&gt;
&lt;p&gt;In bpf_timer_cancel_and_free, this patch frees the timer-&amp;gt;timer
after a rcu grace period. This requires a rcu_head addition
to the &amp;#34;struct bpf_hrtimer&amp;#34;. Another kfree(t) happens in bpf_timer_init,
this does not need a kfree_rcu because it is still under the
spin_lock and timer-&amp;gt;timer has not been visible by others yet.&lt;/p&gt;
&lt;p&gt;In bpf_timer_cancel, rcu_read_lock() is added because this helper
can be used in a non rcu critical section context (e.g. from
a sleepable bpf prog). Other timer-&amp;gt;timer usages in helpers.c
have been audited, bpf_timer_cancel() is the only place where
timer-&amp;gt;timer is used outside of the spin_lock.&lt;/p&gt;
&lt;p&gt;Another solution considered is to mark a t-&amp;gt;flag in bpf_timer_cancel
and clear it after hrtimer_cancel() is done.  In bpf_timer_cancel_and_free,
it busy waits for the flag to be cleared before kfree(t). This patch
goes with a straight forward solution and frees timer-&amp;gt;timer after
a rcu grace period.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-26737</guid>
    </item>
  </channel>
</rss>
