-

CVE-2026-98286

drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown

In the Linux kernel, the following vulnerability has been resolved:

drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown

In drop_monitor teardown paths (net_dm_trace_off_set(),
net_dm_hw_monitor_stop(), and error unwind paths in net_dm_trace_on_set()
and net_dm_hw_monitor_start()), per-CPU timers are stopped using
timer_delete_sync() followed by cancel_work_sync().

However, there is a circular dependency between send_timer and
dm_alert_work:
1) sched_send_work() (timer callback) schedules dm_alert_work.
2) send_dm_alert() / net_dm_hw_summary_work() calls reset_per_cpu_data()
   or net_dm_hw_reset_per_cpu_data().
3) If memory allocation fails under memory pressure in the reset
   function, it re-arms the timer via mod_timer(&data->send_timer, ...).

If dm_alert_work is running concurrently while timer_delete_sync()
executes on another CPU, an allocation failure in the worker will
re-arm the timer after timer_delete_sync() has already returned.
Once cancel_work_sync() completes and module_put() is called, the timer
remains active in the timer wheel. If the module is then unloaded, the
timer will fire and execute sched_send_work() in freed memory,
triggering a kernel panic / use-after-free.

Switch from timer_delete_sync() to timer_shutdown_sync(). This guarantees
that any in-flight timer handler has finished and prevents subsequent
re-arming attempts from running workers from succeeding. When monitoring
is restarted later, timer_setup() is invoked, which cleanly
re-initializes the timer.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9398e9c0b1d44eeb700e9e766c02bcc765c82570
Version < 9616b0c67fbd8cc0b49de7b26cdf2ab33747c80e
Status affected
Version 9398e9c0b1d44eeb700e9e766c02bcc765c82570
Version < bda4d9525fb91a2388ee09669421b8d505290864
Status affected
Version 9398e9c0b1d44eeb700e9e766c02bcc765c82570
Version < c391a40f71886b28c082b47270f0e856fa3e1150
Status affected
Version 2514c7ad115e762562c7bdd58bb1ab3425a98245
Status affected
Version 439b1164da3612ec7e186e1dc314471e7190bfc7
Status affected
Version 5.10.27
Version < 5.11
Status affected
Version 5.11.11
Version < 5.12
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.12
Status affected
Version 0
Version < 5.12
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.062
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9616b0c67fbd8cc0b49de7b26cdf2ab33747c80e
https://git.kernel.org/stable/c/bda4d9525fb91a2388ee09669421b8d505290864
https://git.kernel.org/stable/c/c391a40f71886b28c082b47270f0e856fa3e1150