A KASAN-detected use-after-free race affects Linux kernel RxRPC during network-namespace teardown. In the failing path, rxrpc_destroy_all_peers traverses peer records and attempts to lock a peer that asynchronous RCU-based cleanup has already released, creating a memory-lifetime flaw during repeated namespace destruction.
Kernel maintainers rejected a global rcu_barrier() mitigation because it could block on unrelated callbacks across the system. They instead favor using the pernet_operations pre_exit lifecycle hook to drain RxRPC activity before namespace state becomes invalid; no CVE, confirmed exploit path, affected-version range, or final upstream fix has been established. Linux teams should stress-test network-namespace creation and teardown under KASAN and monitor upstream patches and stable backports.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
During review of the proposed remediation, Eric Dumazet rejected using a global rcu_barrier() because it would wait for unrelated callbacks across the system. He recommended using the pernet_operations pre_exit lifecycle hook to drain RxRPC activity while namespace state remains valid.
A patch review identified a KASAN-detected use-after-free in RxRPC's rxrpc_destroy_all_peers during network-namespace removal, where code could lock a peer already released through asynchronous RCU cleanup. The associated syzbot report included a reproducer and KASAN stack trace.
A separate report described RxRPC connection destruction being moved before network-namespace cleanup had completed. The source states that this issue is distinct and does not establish a shared root cause with the peer use-after-free race.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.