7.5

CVE-2026-74742

veth: fix queue index used to wake the peer txq in veth_poll

In the Linux kernel, the following vulnerability has been resolved:

veth: fix queue index used to wake the peer txq in veth_poll

veth_poll() derives the index of the peer TX queue to wake from
rq->xdp_rxq.queue_index. That field is only initialized by
xdp_rxq_info_reg() in veth_enable_xdp_range(), which runs only when an
XDP program is attached. On the plain GRO/NAPI path
(veth_napi_enable_range()) xdp_rxq_info_reg() is never called, so
queue_index stays 0 for every queue, as priv->rq is zero-allocated.

So in a multi-queue setup with GRO enabled and no XDP program attached,
every NAPI instance looks at the peer's TX queue 0. If veth_xmit() stops
peer TX queue 1 because the ptr_ring is full (NETDEV_TX_BUSY), nothing
ever wakes it again: the poller draining queue 1 wakes queue 0 instead.
veth implements no ndo_tx_timeout, so the netdev watchdog does not kick
in either, and the queue stays stopped indefinitely.

Derive the index from the position of the rq within priv->rq instead,
which is correct regardless of whether XDP was ever enabled.

Scripts to reproduce the stall are available at
https://github.com/netoptimizer/veth-backpressure-performance-testing
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9fe31b3f314534e238aa6d0b6fb492134cbcf8be
Version < b662a1fb4f3a5ea19bac24eea8315b1d05be51e7
Status affected
Version dc82a33297fc2c58cb0b2b008d728668d45c0f6a
Version < 73f8dd22b1e533a99ecc3f9b5de6c6daccaecace
Status affected
Version dc82a33297fc2c58cb0b2b008d728668d45c0f6a
Version < 90bb11fb29d3c55a2c46dc7c386d096b286e7fcf
Status affected
Version dc82a33297fc2c58cb0b2b008d728668d45c0f6a
Version < 60db47f02bfa2aa688938aa199117ec4f8e31d23
Status affected
Version 6.12.61
Version < 6.12.105
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.384
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b662a1fb4f3a5ea19bac24eea8315b1d05be51e7
https://git.kernel.org/stable/c/73f8dd22b1e533a99ecc3f9b5de6c6daccaecace
https://git.kernel.org/stable/c/90bb11fb29d3c55a2c46dc7c386d096b286e7fcf
https://git.kernel.org/stable/c/60db47f02bfa2aa688938aa199117ec4f8e31d23