In the Linux kernel, the following vulnerability has been resolved:
6lowpan: fix NHC entry use-after-free on error path
lowpannhcdouncompression() looks up an NHC descriptor while holding lowpannhc_lock. If the descriptor has no uncompress callback, the error path drops the lock before printing nhc->name.
lowpannhcdel() removes descriptors under the same lock and then relies on synchronizenet() before the owning module can be unloaded. That only waits for net RX RCU readers. lowpanheader_decompress() is also exported and can be reached from callers that are not necessarily covered by the net core RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive path.
This leaves a race where one task drops lowpannhclock in the error path, another task unregisters and frees the matching descriptor after synchronize_net() returns, and the first task then dereferences nhc->name for the warning.
With the post-unlock window widened, KASAN reports:
BUG: KASAN: slab-use-after-free in lowpannhcdouncompression+0x1f4/0x220 Read of size 8 lowpannhcdouncompression lowpanheaderdecompress
Fix this by printing the warning before dropping lowpannhclock, so the descriptor name is read while unregister is still excluded. The malformed packet is still rejected with -ENOTSUPP.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64452.json",
"cna_assigner": "Linux"
}