<?xml version="1.0" encoding="UTF-8"?>
<VrdaData refvuldefversion="1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://vrda.jpcert.or.jp" xsi:schemaLocation="http://vrda.jpcert.or.jp/feed/xsd/vrda_data.xsd">
  <VrdaDataProvider>
    <Name>JVN iPedia</Name>
    <URL>http://jvndb.jvn.jp</URL>
  </VrdaDataProvider>
  <VrdaDataSourceType>Advisory</VrdaDataSourceType>
  <Vulinfo revisionno="1" lang="ja" invalidated="false">
    <VulinfoID>JVNDB-2026-025999</VulinfoID>
    <VulinfoData>
      <Title>Linux&#12398;Linux Kernel&#12395;&#12362;&#12369;&#12427;&#35299;&#25918;&#28168;&#12415;&#12513;&#12514;&#12522;&#12398;&#20351;&#29992;&#12395;&#38306;&#12377;&#12427;&#33030;&#24369;&#24615;</Title>
      <VulinfoDescription>
        <Overview>Linux&#12459;&#12540;&#12493;&#12523;&#12395;&#12362;&#12356;&#12390;&#12289;&#20197;&#19979;&#12398;&#33030;&#24369;&#24615;&#12364;&#20462;&#27491;&#12373;&#12428;&#12414;&#12375;&#12383;&#12290;net/tcp-ao: del_async&#32076;&#36335;&#12395;&#12362;&#12369;&#12427;&#12461;&#12540;&#12398;use-after-free&#12434;&#20462;&#27491;&#12290;tcp_ao_delete_key()&#38306;&#25968;&#12391;&#12399;&#12289;del_async&#32076;&#36335;&#12364;&#21516;&#26399;&#30340;&#32076;&#36335;&#12395;&#23384;&#22312;&#12377;&#12427;current_key&#12362;&#12424;&#12403;rnext_key&#12398;&#26377;&#21177;&#24615;&#12481;&#12455;&#12483;&#12463;&#12434;&#12473;&#12461;&#12483;&#12503;&#12375;&#12390;&#12362;&#12426;&#12289;&#12371;&#12428;&#12425;&#12398;&#12509;&#12452;&#12531;&#12479;&#12399;LISTEN&#12477;&#12465;&#12483;&#12488;&#19978;&#12391;&#12399;&#24120;&#12395;NULL&#12391;&#12354;&#12427;&#12392;&#20206;&#23450;&#12375;&#12390;&#12356;&#12414;&#12375;&#12383;&#12290;&#12375;&#12363;&#12375;&#12289;&#12477;&#12465;&#12483;&#12488;&#12364;CLOSE&#29366;&#24907;&#12395;&#12354;&#12427;&#38291;&#12395;set_current=1/set_rnext=1&#12391;&#12461;&#12540;&#12364;&#36861;&#21152;&#12373;&#12428;&#12383;&#22580;&#21512;&#12289;listen()&#12395;&#12424;&#12387;&#12390;&#12477;&#12465;&#12483;&#12488;&#12364;LISTEN&#29366;&#24907;&#12395;&#36983;&#31227;&#12375;&#12383;&#24460;&#12391;&#12418;&#12289;current_key&#12362;&#12424;&#12403;rnext_key&#12399;NULL&#12391;&#12394;&#12356;&#21487;&#33021;&#24615;&#12364;&#12354;&#12426;&#12414;&#12377;&#12290;&#12371;&#12398;&#12424;&#12358;&#12394;&#12461;&#12540;&#12364;del_async=1&#12391;&#21066;&#38500;&#12373;&#12428;&#12427;&#12392;&#12289;hlist_del_rcu()&#12362;&#12424;&#12403;call_rcu()&#12395;&#12424;&#12387;&#12390;&#12461;&#12540;&#12364;&#35299;&#25918;&#12373;&#12428;&#12414;&#12377;&#12364;&#12289;&#12480;&#12531;&#12464;&#12522;&#12531;&#12464;&#12509;&#12452;&#12531;&#12479;&#12398;&#12463;&#12522;&#12450;&#12364;&#34892;&#12431;&#12428;&#12414;&#12379;&#12435;&#12290;RCU&#12398;&#29494;&#20104;&#26399;&#38291;&#32066;&#20102;&#24460;&#12395;getsockopt(TCP_AO_INFO)&#12364;&#35299;&#25918;&#28168;&#12415;&#12473;&#12521;&#12502;&#12513;&#12514;&#12522;&#12363;&#12425;current_key-&#65310;sndid&#12362;&#12424;&#12403;rnext_key-&#65310;rcvid&#12434;&#21442;&#29031;&#12375;&#12390;&#12375;&#12414;&#12356;&#12414;&#12377;&#12290;del_async&#32076;&#36335;&#12391;&#12399;&#12289;&#21066;&#38500;&#23550;&#35937;&#12398;&#12461;&#12540;&#12434;&#21442;&#29031;&#12375;&#12390;&#12356;&#12427;&#22580;&#21512;&#12289;current_key&#12362;&#12424;&#12403;rnext_key&#12434;&#12463;&#12522;&#12450;&#12377;&#12427;&#12424;&#12358;&#12395;&#20462;&#27491;&#12373;&#12428;&#12414;&#12375;&#12383;&#12290;</Overview>
      </VulinfoDescription>
      <Affected>
        <AffectedItem affectedstatus="vulnerable">
          <Lapt>cpe:/o:linux:linux_kernel</Lapt>
        </AffectedItem>
      </Affected>
      <FactAnalysis>
      </FactAnalysis>
      <Related>
        <RelatedItem relationtype="self" origin="jvnipedia">
          <URL>https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-025999.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2026-53389</VulinfoID>
          <URL>https://www.cve.org/CVERecord?id=CVE-2026-53389</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>National Vulnerability Database (NVD)</Name>
          <VulinfoID>CVE-2026-53389</VulinfoID>
          <URL>https://nvd.nist.gov/vuln/detail/CVE-2026-53389</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>JVNDB</Name>
          <VulinfoID>CWE-416</VulinfoID>
          <Title>&#35299;&#25918;&#28168;&#12415;&#12513;&#12514;&#12522;&#12398;&#20351;&#29992;</Title>
          <URL>https://cwe.mitre.org/data/definitions/416.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>net/tcp-ao: fix use-after-free of key in del_async path - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/5ba9950bc9078e19b69cca1e56d1553b125c6857)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/5ba9950bc9078e19b69cca1e56d1553b125c6857</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>net/tcp-ao: fix use-after-free of key in del_async path - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/7ddc29a094d96e9b3aa280433c6dc443df9eabf2)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/7ddc29a094d96e9b3aa280433c6dc443df9eabf2</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>net/tcp-ao: fix use-after-free of key in del_async path - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/6ce7ef41743740ce15c2061561b784148b565b3f)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/6ce7ef41743740ce15c2061561b784148b565b3f</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>net/tcp-ao: fix use-after-free of key in del_async path - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/e77fbefd1269b5c123e7c651a1ebdce1b87d19a0)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/e77fbefd1269b5c123e7c651a1ebdce1b87d19a0</URL>
        </RelatedItem>
      </Related>
      <DateFirstPublished>2026-07-30T17:44:34+09:00</DateFirstPublished>
      <DateLastUpdated>2026-07-30T17:44:34+09:00</DateLastUpdated>
    </VulinfoData>
  </Vulinfo>
</VrdaData>
