{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  slip: fix use-after-free in sl_sync()  slip_devs[] stores bare net_device pointers and takes no reference on them.  sl_sync() and sl_alloc() walk that table from slip_open() under rtnl_lock(), while an entry is dropped by sl_free_netdev(), which sl_setup() installs as dev-\u003epriv_destructor.  priv_destructor is called from netdev_run_todo(), which deliberately runs with the RTNL semaphore released so that it can sleep while waiting for the device refcount to drop:  \t/* Snapshot list, allow later requests */ \tlist_replace_init(\u0026net_todo_list, \u0026list);  \t__rtnl_unlock(); \t... \t\tif (dev-\u003epriv_destructor) \t\t\tdev-\u003epriv_destructor(dev);\t/* slip_devs[i] = NULL */ \t\tif (dev-\u003eneeds_free_netdev) \t\t\tfree_netdev(dev); \t\t... \t\t/* Free network device */ \t\tkobject_put(\u0026dev-\u003edev.kobj);  So rtnl_lock() does not serialise slip_open() against the teardown at all.  sl_sync() can load slip_devs[i] while the entry is still published and dereference it after netdev_run_todo() has run the destructor and released the device:    CPU0 (slip_open)                 CPU1 (slip_close)                                    unregister_netdev()                                      rtnl_unlock()                                        netdev_run_todo()                                          __rtnl_unlock()   rtnl_lock()   sl_sync()     dev = slip_devs[i]                                          priv_destructor(dev)                                            slip_devs[i] = NULL                                          kobject_put(\u0026dev-\u003edev.kobj)                                            /* dev is freed */     sl = netdev_priv(dev)     if (sl-\u003etty || sl-\u003eleased)     /* use-after-free */    BUG: KASAN: use-after-free in sl_sync drivers/net/slip/slip.c:730 [inline]   BUG: KASAN: use-after-free in slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806   Read of size 1 at addr ffff8880712dac71 by task syz-executor.2/6506    CPU: 2 PID: 6506 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00260-g0c8fc3469765 #0   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014   Call Trace:    sl_sync drivers/net/slip/slip.c:730 [inline]    slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806    tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433    tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564    tiocsetd drivers/tty/tty_io.c:2428 [inline]    tty_ioctl+0x5f0/0x1530 drivers/tty/tty_io.c:2712    Allocated by task 6502:    alloc_netdev_mqs+0x98/0xfe0 net/core/dev.c:10719    sl_alloc drivers/net/slip/slip.c:756 [inline]    slip_open+0x36d/0x1210 drivers/net/slip/slip.c:817    tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433    tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564    Freed by task 6497:    device_release+0xa2/0x240 drivers/base/core.c:2507    kobject_put+0x179/0x280 lib/kobject.c:729    netdev_run_todo+0x6c8/0xef0 net/core/dev.c:10509    slip_close+0x166/0x1c0 drivers/net/slip/slip.c:906    tty_ldisc_close+0x113/0x1a0 drivers/tty/tty_ldisc.c:456    tty_ldisc_kill+0x94/0x160 drivers/tty/tty_ldisc.c:614    tty_ldisc_release+0xe3/0x2b0 drivers/tty/tty_ldisc.c:782    tty_release+0xbcc/0xe70 drivers/tty/tty_io.c:1860  Commit e58c19124189 (\"slip: Fix use-after-free Read in slip_open\") fixed a different source of stale entries - a device left in slip_devs[] after slip_open() freed it on the registration error path - and does not address this race, which is why the report survives it.  Drop the entry from ndo_uninit instead.  unregister_netdevice() calls ndo_uninit under RTNL, before the device is queued to netdev_run_todo(), so an entry that sl_sync() can still see while holding RTNL belongs to a device that cannot be freed until RTNL is dropped.  sl_free_netdev() stays only for the slip_open() error path, where register_netdevice() may have failed before ndo_init and ndo_uninit is then not called either.  Both running for the same device is harmless: the ---truncated---",
  "id": "DEBIAN-CVE-2026-81001",
  "modified": "2026-09-15T08:47:24.891398749Z",
  "published": "2026-09-11T20:19:08.160Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-81001"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-81001"
  ]
}