-

CVE-2026-80841

Medienbericht

net/packet: defer vmalloc TX_RING free until skbs finish

In the Linux kernel, the following vulnerability has been resolved:

net/packet: defer vmalloc TX_RING free until skbs finish

AF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb
page references preserve page-backed ring blocks after pg_vec is freed,
but they do not preserve a vmalloc mapping.

tpacket_destruct_skb() currently drops the pending reference before
writing the timestamp and TP_STATUS_AVAILABLE to the frame. Move the
decrement after those stores. The smp_wmb() in __packet_set_status()
orders the frame stores before the decrement.

Also recheck pending TX frames under pg_vec_lock before non-closing
ring replacement, so a racing send cannot add a pending skb between
the initial check and the ring swap.

Ring allocation can produce a mixture of page-backed and vmalloc-backed
blocks. Allocate deferred-work storage during TX ring setup when the
first vmalloc-backed block is encountered, and keep its pointer in the
pg_vec allocation header. If allocation fails, return -ENOMEM from ring
setup. On socket close, a non-NULL pointer identifies a vmalloc-backed
vector without a scan. If TX skbs remain, defer the whole vector to
system_long_wq.

After pg_vec is detached, a late destructor can skip the pending
decrement. Use socket write-memory accounting as the deferred lifetime
gate instead: an skb remains charged through its final sock_wfree(),
after all ring-frame accesses. The delayed work retains a socket
reference and reschedules itself until no TX skbs remain.

Move pending_refcnt release to packet_sock_destruct() so late skb
destructors and deferred cleanup can safely use it after
packet_release(). Page-backed teardown remains synchronous, and no lock
is added to the TX completion hot path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b013840810c221f2b0cf641d01531526052dc1fb
Version < debf9f50140b3df3949ebcb97d4450f8993fe32d
Status affected
Version b013840810c221f2b0cf641d01531526052dc1fb
Version < 4ce6e2d2e38055b2012bd5fdb0c8a8183c8a1b0c
Status affected
Version b013840810c221f2b0cf641d01531526052dc1fb
Version < ed25ed29034ddc3dbe451ccbaa58ab9932f99d8b
Status affected
Version b013840810c221f2b0cf641d01531526052dc1fb
Version < 0189dce07db2dc059ae0570e06758ec4233c6e11
Status affected
Version b013840810c221f2b0cf641d01531526052dc1fb
Version < 550d00aa58193fb649a09a9c9e338c685adad784
Status affected
Version b013840810c221f2b0cf641d01531526052dc1fb
Version < 992cc9f94ca924089a506ba9b327caa9af797529
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.14
Status affected
Version 0
Version < 3.14
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/0189dce07db2dc059ae0570e06758ec4233c6e11
https://git.kernel.org/stable/c/550d00aa58193fb649a09a9c9e338c685adad784
https://git.kernel.org/stable/c/992cc9f94ca924089a506ba9b327caa9af797529
https://git.kernel.org/stable/c/ed25ed29034ddc3dbe451ccbaa58ab9932f99d8b
https://git.kernel.org/stable/c/4ce6e2d2e38055b2012bd5fdb0c8a8183c8a1b0c
https://git.kernel.org/stable/c/debf9f50140b3df3949ebcb97d4450f8993fe32d