7.8

CVE-2026-97611

net: openvswitch: fix use-after-free of the flow table mask array

In the Linux kernel, the following vulnerability has been resolved:

net: openvswitch: fix use-after-free of the flow table mask array

tbl_mask_array_realloc() retires the old mask_array before it stops being
reachable:

	old = ovsl_dereference(tbl->mask_array);
	if (old) {
		...
		call_rcu(&old->rcu, mask_array_rcu_cb);
	}

	rcu_assign_pointer(tbl->mask_array, new);

call_rcu() only waits for read-side critical sections already in flight.
tbl->mask_array still points at old between the call_rcu() and the
rcu_assign_pointer(), so a reader entering ovs_flow_tbl_lookup_stats() in
that window picks up old in a fresh critical section that the pending
grace period does not cover.

tbl_mask_array_realloc() runs in process context under ovs_mutex, so the
window is preemptible and can outlast the grace period. Then
mask_array_rcu_cb() frees old before the swap runs:

  BUG: KASAN: slab-use-after-free in flow_lookup.constprop.0+0x2bf/0x2f0
  Read of size 8 at addr ffff888020b3e018 by task poc/741
   flow_lookup.constprop.0+0x2bf/0x2f0
   ovs_flow_tbl_lookup_stats+0x4a3/0x5c0
   ovs_dp_process_packet+0x19c/0x710
   ovs_vport_receive+0x243/0x390
   internal_dev_xmit+0x81/0x170
  Freed by task 728:
   kfree+0x16a/0x4e0
   rcu_core+0x853/0x1030

Publish the new array before retiring the old one. The kfree_rcu() that
call_rcu() replaced ran after the swap.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < 4c98b492e9ed63f9ca3e23566d9a6a4f235944f4
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < 4016ead17acd75312c066ecd47c4b7f0a81ceaa2
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < 017dbbf0d6c319a487f68e22f56d91fc787d5525
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < 76678217cdabc41e3c74c23b45b62086ffb8fe7a
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < cd982e11684def5d4a9fcfd5354de09032828414
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < a0d18d21d48a551f82ee344e50efb8a682161489
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < 035e9c3722067648a99010711d0ce81f42572ef4
Status affected
Version eac87c413bf9794c14d488998a5265ea5b32f04e
Version < ba4ba11ed6eb8972c69070417fc27b48deb002e8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.9
Status affected
Version 0
Version < 5.9
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.043
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cd982e11684def5d4a9fcfd5354de09032828414
https://git.kernel.org/stable/c/a0d18d21d48a551f82ee344e50efb8a682161489
https://git.kernel.org/stable/c/035e9c3722067648a99010711d0ce81f42572ef4
https://git.kernel.org/stable/c/ba4ba11ed6eb8972c69070417fc27b48deb002e8
https://git.kernel.org/stable/c/017dbbf0d6c319a487f68e22f56d91fc787d5525
https://git.kernel.org/stable/c/4016ead17acd75312c066ecd47c4b7f0a81ceaa2
https://git.kernel.org/stable/c/4c98b492e9ed63f9ca3e23566d9a6a4f235944f4
https://git.kernel.org/stable/c/76678217cdabc41e3c74c23b45b62086ffb8fe7a