KernelScan.io

HIGH Introduced in 2.6.16

keys RequestKeyAuth UAF

CVE-2026-63823

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach and free rka destroy auth key wake up use rka->target_key **USE-AFTER-FREE** Give request_key_auth payloads a refcount. Take a payload reference while authkey->sem stabilizes the payload and revocation state. Hold that reference across the instantiate and reject paths. Drop the auth key owning reference from revoke and destroy. [jarkko: Replaced the first two paragraphs of text with an actual concurrency scenario.]

02

Engine v0.4.0

Risk summary

A local unprivileged user can trigger a use-after-free in the kernel key management subsystem by racing KEYCTL_INSTANTIATE_IOV against key revocation/destruction. Successful exploitation can lead to arbitrary kernel memory read/write, enabling full privilege escalation to root. The race window requires careful timing but is exploitable without special hardware or configuration.

Affectedsecurity/keys/request_key_auth.c, security/keys/keyctl.c (Linux kernel key management)

Vulnerability analysis

The vulnerability is a use-after-free race condition in the Linux kernel's request_key authentication mechanism. When a key helper process calls KEYCTL_INSTANTIATE_IOV, it loads the request_key_auth (rka) pointer from the auth key's payload and then may sleep on a page fault while copying the user-supplied payload. Concurrently, if the requesting process completes (e.g., times out or the helper finishes via another path), the auth key can be revoked and destroyed, freeing the rka structure. When the sleeping thread wakes up, it dereferences the now-freed rka->target_key, resulting in a use-after-free. The fix introduces a refcount (refcount_t usage) on the request_key_auth structure. The new request_key_auth_get() function takes the authkey->sem read lock, checks the KEY_FLAG_REVOKED flag, and atomically increments the refcount before releasing the lock. The corresponding request_key_auth_put() decrements the refcount and schedules RCU-based freeing only when the last reference is dropped. The revoke and destroy paths now call request_key_auth_put() instead of directly scheduling RCU disposal, ensuring the structure lives until all users have finished. The attack surface requires a local user who can call request_key() and KEYCTL_INSTANTIATE_IOV — available to any unprivileged process — and must win a race condition, making AC:High appropriate.

03

BranchIntroducedFixed inPatch commit
5.152.6.165.15.2114982bfabce6b
6.12.6.166.1.177708709c65a18
6.62.6.166.6.14435ab4db86774
6.122.6.166.12.95f9b68632ac93
6.182.6.166.18.387216ce8cb12f
mainline2.6.167.2-rc1fd15b457a869
7.12.6.167.1.383c0a1cb296d
5.102.6.165.10.260d8274181b0f2