【活用ガイド】

JVNDB-2026-022936

LinuxのLinux Kernelにおける競合状態に関する脆弱性

概要

Linuxカーネルにおいて、以下の脆弱性が修正されました。Bluetoothのhci_uartにおけるcloseおよびinitパスに関連したUse-After-Free(UAF)および競合状態の問題です。hci_uartのライフサイクル管理において、Use-After-Free(UAF)およびヌルポインタ参照(NPD)につながる脆弱性が確認されました。主な問題は、TTYのクローズ時にHCI_UART_PROTO_READYフラグが設定されている場合にのみ、workqueue(init_readyおよびwrite_work)がフラッシュ・キャンセルされている点にあります。セットアップ完了前にハングアップが発生した場合、hci_uart_tty_close()はこれらのworkqueueの解体をスキップして`hu`構造体を解放してしまいます。その後、スケジュールされたworkが実行されると、解放済みの`hu`構造体を盲目的に参照してしまいます。さらに、解体シーケンス内で複数のデータ競合およびUAFが特定されました。第一に、hci_uart_close()からhci_uart_flush()を呼び出す際にwrite_workが効果的に無効化されていないため、両者が同時にhu->tx_skbを二重解放する競合状態が発生しています。これはプロトコルタイマーが同時にhci_uart_tx_wakeup()を呼び出してwrite_workを再キューイングするためです。第二に、hu->proto->close(hu)の前にhci_free_dev(hdev)を呼ぶと、ベンダー固有のプロトコルクローズコールバックがhu->hdevを参照してUAFが発生します。第三に、初期化エラー経路でproto_lockの書き込みロックを取得せずにPROTO_READYをクリアすると、アクティブなリーダーとの競合が発生します。さらに、hci_uart_tty_receive()が読取りロック外でhu->hdevにアクセスするため、初期化エラー経路でhdevが同時に解放されるとUAFが生じます。これらの同期およびライフサイクル問題は以下のように修正されました。まず、hci_uart_tty_close()の処理順序を変更し、最初にHCI_UART_PROTO_READYをクリアした後、即座にcancel_work_sync(&hu->write_work)を実行するようにしました。フラグをクリアすることでプロトコルタイマーがhci_uart_tx_wakeup()を正しく呼び出せなくなり、キャンセルが確実に機能してtx_skbの二重解放を防止しています。次に、PROTO_READYを早期にクリアするとhci_uart_close()がhu->proto->flush()をスキップしますが、tty_closeパス内でhu->proto->close()が直後に実行されるため、これは安全な動作です。close()の呼び出しにより、全プロトコルSKBキューが抹消され、状態が解体されます。さらに、hu->proto->close(hu)をすべてのクローズおよびエラー経路でhci_free_dev(hdev)の直前に移動し、ベンダーレベルのUAFを防止しています。また、hci_uart_tty_receive()内のhdev->stat.byte_rxのインクリメント処理をproto_lockの読取り側クリティカルセクション内に移動し、デバイス登録解除との同期を安全に行うようにしました。加えて、hci_uart_close()にcancel_work_sync(&hu->write_work)を追加し、HCIコアからhci_uart_flush()が呼ばれる前にworkqueueを安全にフラッシュできるようにしています。最後に、すべてのパスでdisable_work_sync()の代わりにcancel_work_sync()を使用することで、ユーザースペースのリトライ機能が永久に失われるのを防止しています。
CVSS による深刻度 (CVSS とは?)

CVSS v3 による深刻度
基本値: 7.8 (重要) [その他]
  • 攻撃元区分: ローカル
  • 攻撃条件の複雑さ: 低
  • 攻撃に必要な特権レベル: 低
  • 利用者の関与: 不要
  • 影響の想定範囲: 変更なし
  • 機密性への影響(C): 高
  • 完全性への影響(I): 高
  • 可用性への影響(A): 高
影響を受けるシステム


Linux
  • Linux Kernel 4.14.203 以上 4.15 未満
  • Linux Kernel 4.19.153 以上 4.20 未満
  • Linux Kernel 5.11 以上 5.15.209 未満
  • Linux Kernel 5.16 以上 6.1.175 未満
  • Linux Kernel 5.4.73 以上 5.5 未満
  • Linux Kernel 5.8.17 以上 5.9 未満
  • Linux Kernel 5.9.2 以上 5.10.258 未満
  • Linux Kernel 6.13 以上 6.18.34 未満
  • Linux Kernel 6.19 以上 7.0.11 未満
  • Linux Kernel 6.2 以上 6.6.142 未満
  • Linux Kernel 6.7 以上 6.12.92 未満
  • Linux Kernel 7.1

想定される影響

・当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。
・当該ソフトウェアが扱う全ての情報が書き換えられる可能性があります。
・当該ソフトウェアが完全に停止する可能性があります。
対策

リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。
ベンダ情報

CWEによる脆弱性タイプ一覧  CWEとは?

  1. 競合状態(CWE-362) [NVD評価]
共通脆弱性識別子(CVE)  CVEとは?

  1. CVE-2026-46275
参考情報

  1. National Vulnerability Database (NVD) : CVE-2026-46275
  2. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/e2d19969c8d9198ecc3090bcd5312ecd503a3339)
  3. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/7338031946bd06f6dff149e67b60c4cd083bfea8)
  4. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/9d20d48be2c4a071fb015eb09bda2cecd25daf34)
  5. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/78aad93e938f013d9272fe0ee168f27883afa95c)
  6. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/81c7a3c22a0f2808cf4ae0b4908f59763b23606d)
  7. 関連文書 : https://git.kernel.org/stable/c/192cb0f1ca706d9a1bc36ae0ad5f666d1e4fd894
  8. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/c1bb9336ae6b54a5f6a353c4bd4ed9a4307e429b)
  9. 関連文書 : Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/c85cff648a2bc92322912db5f1727ad05afae7b6)
更新履歴

  • [2026年07月10日]
      掲載