Canonical has published Kernel Live Patch Security Notice LSN-0122-1, resolving three distinct memory-safety vulnerabilities in the Linux kernel. Two of the three are use-after-free (UAF) conditions — a bug class that ranks among the most dangerous in kernel space — and the third is a NULL pointer dereference in a widely deployed Broadcom/Cypress Wi-Fi driver. All three were surfaced through KASAN (Kernel Address Sanitizer) reports, and all three carry at minimum denial-of-service impact with the potential, in the UAF cases, for escalation to arbitrary code execution under the right heap conditions.
The practical takeaway for defenders: any Ubuntu system running an affected kernel — particularly HA clusters using the Distributed Lock Manager, laptops and embedded devices with Broadcom SDIO Wi-Fi, and multi-CPU systems under parallel packet-processing load — should consume this live patch immediately or schedule a kernel update. Live patching means you can close the exposure without a reboot, which removes the most common excuse for kernel patch latency.
Technical Analysis
Affected Components
This notice bundles fixes for three independent kernel subsystems:
1. fs/dlm — Use-After-Free in midcomms commit path
The Distributed Lock Manager (DLM) is the kernel component that coordinates locking across cluster filesystems such as GFS2 and OCFS2. While processing a DLM message in softirq context, the kernel can reference memory that has already been freed in the midcomms commit path, producing a KASAN use-after-free report. DLM messages arrive over the network (TCP, typically port 21064), which means the vulnerable code path is reachable by network input on clustered systems — any peer able to inject or corrupt DLM traffic can potentially drive the kernel into this freed-memory access.
2. wifi/brcmfmac — NULL pointer dereference in brcmf_sdiod_sglist_rw()
The Broadcom FullMAC SDIO driver contains a NULL dereference triggered when a high sd_sgentry_align value (e.g., 512) is in effect and a large number of queued SKBs (socket buffers) are transmitted from the packet queue. The scatter-gather list construction fails to account for the alignment constraint, dereferencing a NULL pointer and producing a kernel oops. This is a stability/availability bug affecting systems with Broadcom/Cypress SDIO Wi-Fi — a large installed base of laptops, SBCs (Raspberry Pi class devices), and embedded platforms. The trigger condition is high transmit queue pressure, meaning an attacker in radio range or a workload that saturates the wireless link can crash the kernel.
3. padata — Use-After-Free in padata_reorder
padata is the kernel's framework for parallelizing CPU-intensive work across cores — it's used by IPsec (pcrypt), page migration, and other throughput-sensitive paths. Discovered during LTP (Linux Test Project) testing, the bug manifests as:
BUG: KASAN: slab-use-after-free in padata_find_next+0x29/0x1a0
Read of size 4 at addr ffff88b...
The reorder logic reads from a slab object after it has been freed — a race condition inherent to parallel job completion ordering. Because padata underpins cryptographic offload, sustained IPsec traffic on a multi-core system is a realistic trigger.
Severity and Exploitation Assessment
- CVSS/CVE identifiers: The notice summary does not assign specific CVE IDs in the published text; these are upstream kernel fixes distributed under the LSN tracker. Track the notice URL for CVE mappings as Canonical finalizes them.
- Impact: All three are confirmed kernel-memory-safety defects. Minimum impact is kernel panic / system crash (DoS). UAF conditions in DLM and padata are the higher-concern items: kernel UAFs are historically the primitive class most often developed into local privilege escalation exploits, though there is no public PoC, no confirmed in-the-wild exploitation, and no CISA KEV listing for any of these issues as of this writing.
- Attack surface notes:
- DLM: Network-reachable on cluster nodes; requires the attacker to interact with DLM traffic. Highest priority for clustered storage environments.
- brcmfmac: Requires the SDIO Wi-Fi hardware and transmit-queue pressure; proximity or traffic-flooding scenarios.
- padata: Triggerable locally under parallel crypto load; most relevant on multi-tenant hosts and IPsec gateways.
The shared thread: these are availability-destroying bugs in code paths reachable under operational load, and two of them are UAFs that warrant treatment as potential escalation primitives until proven otherwise.
Detection & Response
Kernel memory-safety bugs announce themselves — when they fire — through KASAN reports, kernel oopses, and panics. The most reliable detection strategy is centralized monitoring of kernel logs for these signatures, plus proactive identification of vulnerable systems. Because these flaws live in kernel space, EDR user-mode telemetry will not see the exploitation attempt itself; log telemetry is your signal.
Sigma Rules
---
title: Linux Kernel KASAN Use-After-Free Report
description: Detects KASAN use-after-free and slab-out-of-bounds reports in kernel logs, including signatures matching the DLM midcomms and padata_reorder flaws addressed in Ubuntu LSN-0122-1.
author: Security Arsenal
date: 2026/02/14
status: experimental
references:
- https://ubuntu.com/security/notices/LSN-0122-1
logsource:
product: linux
service: syslog
detection:
selection_kasan:
- 'KASAN: slab-use-after-free'
- 'KASAN: use-after-free'
- 'KASAN: slab-out-of-bounds'
selection_functions:
- 'padata_find_next'
- 'padata_reorder'
- 'dlm'
condition: selection_kasan or (selection_functions and selection_kasan)
falsepositives:
- Kernel fuzzing or syzkaller testing in lab environments
level: high
---
title: Linux Kernel Oops or NULL Pointer Dereference in Wi-Fi Driver
description: Detects kernel oops and NULL pointer dereference events, including the brcmfmac brcmf_sdiod_sglist_rw crash condition from Ubuntu LSN-0122-1.
author: Security Arsenal
date: 2026/02/14
status: experimental
references:
- https://ubuntu.com/security/notices/LSN-0122-1
logsource:
product: linux
service: syslog
detection:
selection_crash:
- 'BUG: unable to handle kernel NULL pointer dereference'
- 'kernel NULL pointer dereference'
- 'Oops:'
- 'general protection fault'
selection_driver:
- 'brcmfmac'
- 'brcmf_sdiod_sglist_rw'
condition: selection_crash and selection_driver
falsepositives:
- None expected; a matching oops indicates an actual kernel fault
level: high
---
title: Unexpected Kernel Panic or Repeated Soft Lockup on Linux Host
description: Detects kernel panics and soft lockups that may indicate exploitation or triggering of kernel memory-safety bugs such as the DLM and padata UAF conditions in LSN-0122-1.
author: Security Arsenal
date: 2026/02/14
status: experimental
references:
- https://ubuntu.com/security/notices/LSN-0122-1
logsource:
product: linux
service: syslog
detection:
selection:
- 'Kernel panic - not syncing'
- 'watchdog: BUG: soft lockup'
- 'rcu_sched self-detected stall'
- 'hung_task: blocked tasks'
falsepositives:
- Hardware faults, resource exhaustion, driver instability unrelated to exploitation
level: medium
KQL — Microsoft Sentinel (Syslog/CEF ingestion)
This query hunts across ingested Linux syslog for the kernel-fault signatures associated with all three flaws, and pivots to identify hosts producing repeated crash events — a pattern consistent with an attacker repeatedly triggering the condition.
// Hunt for kernel memory-safety fault signatures related to LSN-0122-1
let FaultSignatures = dynamic([
"slab-use-after-free",
"KASAN: use-after-free",
"padata_find_next",
"padata_reorder",
"brcmf_sdiod_sglist_rw",
"brcmfmac",
"NULL pointer dereference",
"Kernel panic - not syncing",
"Oops:"
]);
Syslog
| where TimeGenerated > ago(7d)
| where Facility in ("kern", "kernel") or ProcessName =~ "kernel"
| where SyslogMessage has_any (FaultSignatures)
| summarize EventCount = count(),
Signatures = make_set(strcat_array(split(SyslogMessage, " ")[0..3], " ")),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated)
by Computer, HostIP
| extend RepeatedCrashes = EventCount >= 3
| order by EventCount desc;
For environments with cluster storage, this companion query identifies DLM-facing hosts so you can prioritize patching:
// Identify hosts with DLM cluster traffic (TCP 21064) to prioritize LSN-0122-1 patching
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemotePort == 21064 or LocalPort == 21064
| summarize Connections = count(), Peers = dcount(RemoteIP) by DeviceName, LocalIP
| order by Connections desc;
Velociraptor VQL
This artifact sweeps endpoints for recent kernel-fault evidence in system logs, giving incident responders a fleet-wide view of crash artifacts that match the LSN-0122-1 signatures:
-- Hunt kernel logs for UAF / NULL-deref signatures matching LSN-0122-1 flaws
LET log_files = SELECT FullPath
FROM glob(globs=['/var/log/kern.log*', '/var/log/syslog*', '/var/log/messages*'])
WHERE NOT FullPath =~ '\\.gz$'
SELECT FullPath,
Line,
timestamp(string=Timestamp) AS EventTime
FROM foreach(row=log_files,
query={
SELECT FullPath, Line,
split(string=Line, sep=' ')[0..2] AS Timestamp
FROM parse_lines(filename=FullPath)
WHERE Line =~ 'slab-use-after-free|KASAN|padata_find_next|padata_reorder|brcmf_sdiod_sglist_rw|NULL pointer dereference|Kernel panic'
})
ORDER BY EventTime DESC
LIMIT 500
Remediation & Verification Script
The following Bash script checks whether the host is running an affected kernel, verifies Canonical Livepatch status, applies the live patch (or full kernel updates where livepatch is unavailable), and captures any existing crash evidence before remediation:
#!/bin/bash
# LSN-0122-1 verification and remediation script — Security Arsenal
# Run as root. Test in staging before fleet deployment.
echo "=== Current kernel ==="
uname -r
echo "=== Checking for existing crash evidence ==="
dmesg 2>/dev/null | grep -iE 'slab-use-after-free|KASAN|padata_find_next|brcmf_sdiod_sglist_rw|NULL pointer dereference' && \
echo "[!] Kernel fault signatures found — preserve logs and investigate before rebooting" || \
echo "[+] No matching fault signatures in current dmesg"
echo "=== Canonical Livepatch status ==="
if command -v canonical-livepatch &>/dev/null; then
canonical-livepatch status --verbose
echo "=== Forcing livepatch refresh to pull LSN-0122-1 ==="
canonical-livepatch refresh
else
echo "[!] canonical-livepatch not installed — falling back to standard kernel update path"
fi
echo "=== Applying kernel security updates ==="
apt-get update
apt-get install -y --only-upgrade linux-image-$(uname -r) linux-image-generic || \
apt-get dist-upgrade -y
echo "=== Post-update verification ==="
canonical-livepatch status 2>/dev/null | grep -iE 'LSN-0122|patch-state'
apt list --installed 2>/dev/null | grep linux-image | head -5
echo "=== Checking vulnerable components present ==="
lsmod | grep -E '^dlm|^brcmfmac' && echo "[!] Affected modules loaded — patch required" || echo "[+] dlm/brcmfmac not currently loaded"
echo "=== Done. Schedule reboot at next window if live patch did not fully apply. ==="
Remediation
- Apply the live patch immediately. Systems enrolled in Canonical Livepatch (free for up to 5 machines with an Ubuntu One account; included with Ubuntu Pro) receive LSN-0122-1 fixes without a reboot. Verify with
canonical-livepatch status --verboseand force a refresh withcanonical-livepatch refresh. - If not using Livepatch, update the kernel package via
apt update && apt upgradeand schedule a reboot into the patched kernel. Track the official advisory at https://ubuntu.com/security/notices/LSN-0122-1 for the specific patched kernel versions per Ubuntu release (22.04 LTS, 24.04 LTS, and interim releases). - Prioritize by exposure tier:
- Tier 1: Cluster nodes running DLM (GFS2/OCFS2, clustered LVM, Pacemaker with dlm_controld) — the DLM UAF is network-reachable. Patch first; restrict TCP 21064 to known cluster peers via firewall in the interim.
- Tier 2: IPsec VPN gateways and multi-core hosts with heavy padata utilization.
- Tier 3: Endpoints and embedded devices with Broadcom/Cypress SDIO Wi-Fi. Mitigation for unpatched devices includes reducing transmit-queue saturation risk; on systems where Wi-Fi is unused,
echo 'blacklist brcmfmac' >> /etc/modprobe.d/blacklist-brcm.confand unload the module.
- Unload unused modules as a hardening measure — if
dlmorbrcmfmacis loaded on a host that does not need it, remove it from the attack surface permanently. - Enable kdump and persistent kernel logging (
journalctl --bootretention, remote syslog forkern.*) so that if a crash does occur — accidentally or via exploitation — you capture the oops for forensic analysis. A KASAN trace on a production host is a finding, not noise. - Monitor for repeat crashes. A host crashing repeatedly in the same kernel function is either defective hardware or a targeted trigger — treat repeated
padata_find_nextor DLM-area faults as an incident until ruled out.
No CVE-based CISA KEV deadline currently applies to these fixes, but given that two of the three are kernel UAFs — the primitive class behind the majority of Linux local-privilege-escalation exploits — a 72-hour patch SLA for Tier 1 systems is the prudent internal standard.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.