7.8
CVE-2026-97611
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:22:20
- Zuletzt bearbeitet 03.10.2026 11:18:07
- Erkennungen
net: openvswitch: fix use-after-free of the flow table mask array
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix use-after-free of the flow table mask array
tbl_mask_array_realloc() retires the old mask_array before it stops being
reachable:
old = ovsl_dereference(tbl->mask_array);
if (old) {
...
call_rcu(&old->rcu, mask_array_rcu_cb);
}
rcu_assign_pointer(tbl->mask_array, new);
call_rcu() only waits for read-side critical sections already in flight.
tbl->mask_array still points at old between the call_rcu() and the
rcu_assign_pointer(), so a reader entering ovs_flow_tbl_lookup_stats() in
that window picks up old in a fresh critical section that the pending
grace period does not cover.
tbl_mask_array_realloc() runs in process context under ovs_mutex, so the
window is preemptible and can outlast the grace period. Then
mask_array_rcu_cb() frees old before the swap runs:
BUG: KASAN: slab-use-after-free in flow_lookup.constprop.0+0x2bf/0x2f0
Read of size 8 at addr ffff888020b3e018 by task poc/741
flow_lookup.constprop.0+0x2bf/0x2f0
ovs_flow_tbl_lookup_stats+0x4a3/0x5c0
ovs_dp_process_packet+0x19c/0x710
ovs_vport_receive+0x243/0x390
internal_dev_xmit+0x81/0x170
Freed by task 728:
kfree+0x16a/0x4e0
rcu_core+0x853/0x1030
Publish the new array before retiring the old one. The kfree_rcu() that
call_rcu() replaced ran after the swap.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
4c98b492e9ed63f9ca3e23566d9a6a4f235944f4
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
4016ead17acd75312c066ecd47c4b7f0a81ceaa2
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
017dbbf0d6c319a487f68e22f56d91fc787d5525
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
76678217cdabc41e3c74c23b45b62086ffb8fe7a
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
cd982e11684def5d4a9fcfd5354de09032828414
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
a0d18d21d48a551f82ee344e50efb8a682161489
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
035e9c3722067648a99010711d0ce81f42572ef4
Status
affected
Version
eac87c413bf9794c14d488998a5265ea5b32f04e
Version <
ba4ba11ed6eb8972c69070417fc27b48deb002e8
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.9
Status
affected
Version
0
Version <
5.9
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.043 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/cd982e11684def5d4a9fcfd5354de09032828414
https://git.kernel.org/stable/c/a0d18d21d48a551f82ee344e50efb8a682161489
https://git.kernel.org/stable/c/035e9c3722067648a99010711d0ce81f42572ef4
https://git.kernel.org/stable/c/ba4ba11ed6eb8972c69070417fc27b48deb002e8
https://git.kernel.org/stable/c/017dbbf0d6c319a487f68e22f56d91fc787d5525
https://git.kernel.org/stable/c/4016ead17acd75312c066ecd47c4b7f0a81ceaa2
https://git.kernel.org/stable/c/4c98b492e9ed63f9ca3e23566d9a6a4f235944f4
https://git.kernel.org/stable/c/76678217cdabc41e3c74c23b45b62086ffb8fe7a