<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:51:18 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-46936 — net: fix use-after-free in tw_timer_handler</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-46936</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fix use-after-free in tw_timer_handler&lt;/p&gt;
&lt;p&gt;A real world panic issue was found as follow in Linux 5.4.&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffde49a863de28
    PGD 7e6fe62067 P4D 7e6fe62067 PUD 7e6fe63067 PMD f51e064067 PTE 0
    RIP: 0010:tw_timer_handler+0x20/0x40
    Call Trace:
     &amp;lt;IRQ&amp;gt;
     call_timer_fn+0x2b/0x120
     run_timer_softirq+0x1ef/0x450
     __do_softirq+0x10d/0x2b8
     irq_exit+0xc7/0xd0
     smp_apic_timer_interrupt+0x68/0x120
     apic_timer_interrupt+0xf/0x20&lt;/p&gt;
&lt;p&gt;This issue was also reported since 2017 in the thread [1],
unfortunately, the issue was still can be reproduced after fixing
DCCP.&lt;/p&gt;
&lt;p&gt;The ipv4_mib_exit_net is called before tcp_sk_exit_batch when a net
namespace is destroyed since tcp_sk_ops is registered befrore
ipv4_mib_ops, which means tcp_sk_ops is in the front of ipv4_mib_ops
in the list of pernet_list. There will be a use-after-free on
net-&amp;gt;mib.net_statistics in tw_timer_handler after ipv4_mib_exit_net
if there are some inflight time-wait timers.&lt;/p&gt;
&lt;p&gt;This bug is not introduced by commit f2bf415cfed7 (&amp;#34;mib: add net to
NET_ADD_STATS_BH&amp;#34;) since the net_statistics is a global variable
instead of dynamic allocation and freeing. Actually, commit
61a7e26028b9 (&amp;#34;mib: put net statistics on struct net&amp;#34;) introduces
the bug since it put net statistics on struct net and free it when
net namespace is destroyed.&lt;/p&gt;
&lt;p&gt;Moving init_ipv4_mibs() to the front of tcp_init() to fix this…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fix use-after-free in tw_timer_handler&lt;/p&gt;
&lt;p&gt;A real world panic issue was found as follow in Linux 5.4.&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffde49a863de28
    PGD 7e6fe62067 P4D 7e6fe62067 PUD 7e6fe63067 PMD f51e064067 PTE 0
    RIP: 0010:tw_timer_handler+0x20/0x40
    Call Trace:
     &amp;lt;IRQ&amp;gt;
     call_timer_fn+0x2b/0x120
     run_timer_softirq+0x1ef/0x450
     __do_softirq+0x10d/0x2b8
     irq_exit+0xc7/0xd0
     smp_apic_timer_interrupt+0x68/0x120
     apic_timer_interrupt+0xf/0x20&lt;/p&gt;
&lt;p&gt;This issue was also reported since 2017 in the thread [1],
unfortunately, the issue was still can be reproduced after fixing
DCCP.&lt;/p&gt;
&lt;p&gt;The ipv4_mib_exit_net is called before tcp_sk_exit_batch when a net
namespace is destroyed since tcp_sk_ops is registered befrore
ipv4_mib_ops, which means tcp_sk_ops is in the front of ipv4_mib_ops
in the list of pernet_list. There will be a use-after-free on
net-&amp;gt;mib.net_statistics in tw_timer_handler after ipv4_mib_exit_net
if there are some inflight time-wait timers.&lt;/p&gt;
&lt;p&gt;This bug is not introduced by commit f2bf415cfed7 (&amp;#34;mib: add net to
NET_ADD_STATS_BH&amp;#34;) since the net_statistics is a global variable
instead of dynamic allocation and freeing. Actually, commit
61a7e26028b9 (&amp;#34;mib: put net statistics on struct net&amp;#34;) introduces
the bug since it put net statistics on struct net and free it when
net namespace is destroyed.&lt;/p&gt;
&lt;p&gt;Moving init_ipv4_mibs() to the front of tcp_init() to fix this…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-46936</guid>
    </item>
  </channel>
</rss>
