-

CVE-2026-80851

Medienbericht

gtp: serialize PDP context updates

In the Linux kernel, the following vulnerability has been resolved:

gtp: serialize PDP context updates

PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP
network device is being unregistered. The latter is serialized by RTNL,
but the generic-netlink delete path only holds RCU.

Running both paths concurrently can therefore make both paths delete the
same PDP context. The issue was found through static analysis and
reproduced on a KASAN-enabled kernel by a simple two-thread program
racing GTP_CMD_DELPDP against RTM_DELLINK:

  Oops: general protection fault, probably for non-canonical address
  KASAN: maybe wild-memory-access in range
         [0xdead000000000120-0xdead000000000127]
  RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]
  RBP: dead000000000122

The second deletion dereferenced the poisoned hlist pprev pointer.

Serialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a
shared mutex. Keep the mutex held until the final use of a PDP context in
the NEWPDP path, and keep the RCU read-side section around the complete
PDP context use in the DELPDP path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 459aa660eb1d8ce67080da1983bb81d716aa5a69
Version < b4ac2a5ce5a96ec21ed48f60d30b52b1fb22c62a
Status affected
Version 459aa660eb1d8ce67080da1983bb81d716aa5a69
Version < 5f77ddb2756340c1b05381674ca025d52998005e
Status affected
Version 459aa660eb1d8ce67080da1983bb81d716aa5a69
Version < 3d950e98f74af9611925a5226edced02155f6ed1
Status affected
Version 459aa660eb1d8ce67080da1983bb81d716aa5a69
Version < 6df4f05bc2991467939d7d80b6f7e121559cc3df
Status affected
Version 459aa660eb1d8ce67080da1983bb81d716aa5a69
Version < 1e995498d29784a06a2b2899370a1926cfc8410d
Status affected
Version 459aa660eb1d8ce67080da1983bb81d716aa5a69
Version < 498386b6d402737db1e2eeed4c385acbf0ef9e34
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version 0
Version < 4.7
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.108
Status unaffected
Version <= 6.18.*
Version 6.18.49
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/5f77ddb2756340c1b05381674ca025d52998005e
https://git.kernel.org/stable/c/3d950e98f74af9611925a5226edced02155f6ed1
https://git.kernel.org/stable/c/6df4f05bc2991467939d7d80b6f7e121559cc3df
https://git.kernel.org/stable/c/1e995498d29784a06a2b2899370a1926cfc8410d
https://git.kernel.org/stable/c/498386b6d402737db1e2eeed4c385acbf0ef9e34
https://git.kernel.org/stable/c/b4ac2a5ce5a96ec21ed48f60d30b52b1fb22c62a