-

CVE-2026-90201

net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race

In the Linux kernel, the following vulnerability has been resolved:

net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race

This bug was discovered while testing the hns3 driver under channel
reconfiguration (`ethtool -L` / `ethtool -G`) with iperf3 traffic on
arm64. The race is intermittently triggered when page_pool_destroy()
runs page_pool_scrub() concurrently with page return via
page_pool_put_netmem() on a different CPU. A WARN in
page_pool_clear_pp_info() surfaced the dangling DMA index bits left
by the cmpxchg loser, which led to the investigation.

page_pool_scrub() iterates pool->dma_mapped via xa_for_each() with no
page ref held. __page_pool_release_netmem_dma() currently reads and
writes netmem fields (dma_addr, DMA index bits in pp_magic) after
xa_cmpxchg() returns. The unref path calls put_page() unconditionally
regardless of the cmpxchg outcome; when it loses the cmpxchg, it still
frees the page before the scrub winner finishes these netmem accesses,
so scrub touches a freed page -- a Use-After-Free.

Fix this by splitting the DMA release into two functions:

1. __page_pool_unmap_netmem_dma() caches dma_addr before xa_cmpxchg(),
   does the cmpxchg to remove the DMA mapping, and calls dma_unmap on
   the cached address. It never touches netmem fields after the cmpxchg,
   making it safe for the scrub path which holds no page ref.

2. __page_pool_release_netmem_dma() wraps the above and additionally
   clears dma_addr and DMA index bits in netmem fields. This is safe
   only when the caller holds a page ref, so it is used by the return
   path (page_pool_return_netmem).

The scrub path calls __page_pool_unmap_netmem_dma() directly; the return
path calls __page_pool_release_netmem_dma().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4f51fb0d257ff4d406ec27966902de075e3b118e
Version < bbfef303f980c1c078b8fa142e10a0e2fbcdd247
Status affected
Version ee62ce7a1d909ccba0399680a03c2dee83bcae95
Version < 424a9fc4876cc7f28e9cb0aa8d92e920d726e350
Status affected
Version ee62ce7a1d909ccba0399680a03c2dee83bcae95
Version < 9b65b0253ad5a66f73efee9a79a21a1e2b57cf59
Status affected
Version ee62ce7a1d909ccba0399680a03c2dee83bcae95
Version < 24ef02f934eeb48830cff6b739abc3c62b1d107b
Status affected
Version c30ae60f41f9edd6e1b5cad41cf28ce04dae39e4
Status affected
Version 6.12.34
Version < 6.12.110
Status affected
Version 6.15.3
Version < 6.16
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/bbfef303f980c1c078b8fa142e10a0e2fbcdd247
https://git.kernel.org/stable/c/424a9fc4876cc7f28e9cb0aa8d92e920d726e350
https://git.kernel.org/stable/c/9b65b0253ad5a66f73efee9a79a21a1e2b57cf59
https://git.kernel.org/stable/c/24ef02f934eeb48830cff6b739abc3c62b1d107b