-

CVE-2026-90113

netdevsim: update queue NAPI association on queue reset

In the Linux kernel, the following vulnerability has been resolved:

netdevsim: update queue NAPI association on queue reset

In netdevsim, receive queues (struct nsim_rq) embed their own struct
napi_struct. When queue reset is performed (e.g. via queue_reset
debugfs), nsim_queue_start() swaps in a newly allocated struct nsim_rq,
and nsim_queue_mem_free() later deletes and frees the old one.

However, nsim_queue_start() failed to update the queue-to-NAPI mapping
via netif_queue_set_napi(). As a result, dev->_rx[idx].napi continued to
point to the old NAPI struct. After the old queue was freed, a subsequent
queue dump via Netlink (NETDEV_CMD_QUEUE_GET) triggered a KASAN
slab-use-after-free read in nla_put_napi_id() when accessing
rxq->napi->napi_id.

Fix this by calling netif_queue_set_napi() in nsim_queue_start() to
associate the new NAPI with the RX queue, and clear the association
with netif_queue_set_napi(..., NULL) in nsim_del_napi() during teardown.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5bc8e8dbef27b73bd7b6d1fd5108b4fd4c6d469f
Version < b8f32b0804b4bf0cba0ee0a093e3fd74f11d7166
Status affected
Version 5bc8e8dbef27b73bd7b6d1fd5108b4fd4c6d469f
Version < db038ac4dca0fa626199e9c297eddd8362be0550
Status affected
Version 5bc8e8dbef27b73bd7b6d1fd5108b4fd4c6d469f
Version < 07e98a4d5e9c292eae97c9cc5ab0937384e48492
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b8f32b0804b4bf0cba0ee0a093e3fd74f11d7166
https://git.kernel.org/stable/c/db038ac4dca0fa626199e9c297eddd8362be0550
https://git.kernel.org/stable/c/07e98a4d5e9c292eae97c9cc5ab0937384e48492