7.8

CVE-2026-80994

net: openvswitch: fix flow mask use-after-free on flow deletion

In the Linux kernel, the following vulnerability has been resolved:

net: openvswitch: fix flow mask use-after-free on flow deletion

The commit in the Fixes tag below made so flow->mask free is scheduled
via RCU right after it is removed from the flow table.  The pointer
stays in the flow structure and it can be accessible while in the same
RCU critical section.  This is done to avoid requiring ovs_mutex for
the ovs_flow_free().

However, while removing the flow during processing of CMD_DEL, we do
not take RCU read lock before the removal, and ovs_flow_cmd_fill_info()
uses the flow->mask pointer afterwards.  The RCU read lock is taken,
but it's already late at that point.  The comment on that line
acknowledges that the lock is cosmetic and doesn't serve a real purpose.

This leads to use-after-free if the RCU grace period passes between
removal and the filling.  It is a short race window, but it is there
and can lead to a real crash in case memory allocation for the info
takes a bit longer:

 BUG: KASAN: slab-use-after-free in __ovs_nla_put_key
             net/openvswitch/flow_netlink.c:1996
 BUG: KASAN: slab-use-after-free in ovs_nla_put_key+0x2463/0x2e30
             net/openvswitch/flow_netlink.c:2250
 Read of size 4 at addr ffff88801ee89970 by task ovs_flow_del_ec/9487

 Call Trace:
  <TASK>
  __ovs_nla_put_key net/openvswitch/flow_netlink.c:1996
  ovs_nla_put_key+0x2463/0x2e30 net/openvswitch/flow_netlink.c:2250
  ovs_flow_cmd_fill_info+0x420/0x9c0 net/openvswitch/datapath.c:930
  ovs_flow_cmd_del+0x53a/0x970 net/openvswitch/datapath.c:1467
  ...
  netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556
  </TASK>

 Allocated by task 9487:
  mask_alloc net/openvswitch/flow_table.c:967
  flow_mask_insert net/openvswitch/flow_table.c:1012
  ovs_flow_tbl_insert+0xea2/0x1a90 net/openvswitch/flow_table.c:1084
  ovs_flow_cmd_new+0x7e3/0xd90 net/openvswitch/datapath.c:1086
  ...
  netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556

 Freed by task 9485:
  rcu_free_sheaf+0x1e/0x100 mm/slub.c:5978
  rcu_do_batch kernel/rcu/tree.c:2645
  rcu_core+0x59c/0x10c0 kernel/rcu/tree.c:2897
  handle_softirqs+0x1e4/0x9a0 kernel/softirq.c:622
  ...
  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062

ovs_flow_tbl_remove() must be called after the ovs_flow_cmd_fill_info()
to avoid this race.  This also helps with cleaning up the forced cast
and the cosmetic RCU read lock.  Before the commit in the Fixes tag the
order did not matter as long as the flow object itself was not freed.

A wider RCU critical section could be another option, but we have a
GFP_KERNEL allocation in the way.

Reported by Trend Micro's Zero Day Initiative as ZDI-CAN-32042.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < ea5f7b45b582665541ddfb77dce98611354af4ab
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < 18ce1a8b7499c016d4a893d9b1db80608f73745d
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < c15ef9a5bf594f93a31de2ec2ec394e2a903519a
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < 64051fe200c7c759af71634bd2123552eaabb69a
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < 0ba5cbc2f049af94ec94ff6f64958545efc5eaa2
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < ac73e3af571da06c1d1cfe3f0f00dc978b851700
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < 7f072b84afd05a77963eb1872f7174e280661dce
Status affected
Version 56c19868e115fcf8d62d843e1b9616bb9837d0db
Version < 4e30317ff67a2eb12b4d890d39f72fd7e7117d48
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.16
Status affected
Version 0
Version < 3.16
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0ba5cbc2f049af94ec94ff6f64958545efc5eaa2
https://git.kernel.org/stable/c/ac73e3af571da06c1d1cfe3f0f00dc978b851700
https://git.kernel.org/stable/c/7f072b84afd05a77963eb1872f7174e280661dce
https://git.kernel.org/stable/c/4e30317ff67a2eb12b4d890d39f72fd7e7117d48
https://git.kernel.org/stable/c/18ce1a8b7499c016d4a893d9b1db80608f73745d
https://git.kernel.org/stable/c/64051fe200c7c759af71634bd2123552eaabb69a
https://git.kernel.org/stable/c/c15ef9a5bf594f93a31de2ec2ec394e2a903519a
https://git.kernel.org/stable/c/ea5f7b45b582665541ddfb77dce98611354af4ab