« Volver al listado

CVE-2026-74623

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: atlantic: free stranded TX buffers on ring deinit

aq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean() call, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and stops at hw_head, which no longer moves once aq_vec_stop() has stopped the hardware and NAPI. Completed descriptors beyond the budget and everything still posted in [hw_head, sw_tail) keep their skb or xdp_frame when the interface goes down: aq_vec_ring_free() then frees the buffer ring and the references are lost for good.

Today this is a silent memory leak on every interface down under TX/XDP_TX load.

Leer descripción completaMostrar menos

With the conversion of the RX path to page_pool posted for net-next it becomes much more visible: XDP_TX frames carry fragment references on the RX ring's page_pool, so a single stranded frame keeps the pool's inflight count above zero forever. page_pool_destroy() then never completes, the pool is leaked together with its pages, and "page_pool_release_retry() stalled pool shutdown" is warned every 60 seconds from that point on, on every ifdown, XDP detach or ring resize under XDP_TX load.

Bring back aq_ring_tx_deinit() as it was before the removal and use it for teardown again, with one extension: TX rings can hold xdp_frames nowadays, so release those too. They are returned with xdp_return_frame() since this runs in process context.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74623",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "a14ceebd13bf857bfca052bc5a6bd49e737912be",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "4f1c20873f70b4b22ef86dc38dad1fda8e169bcd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "307d80193b4a4a75b8dc4e0d3162be3755abbed7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "3447641d361dcc5511841d986ad4d849b2900d9b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "b13202d401e1a20fec89b0cda733dcbaf279f79d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "dd633280de7fdfd60dc4fcf63d04e2ad95b43269",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb36bedf28be6d986bdbcfa375bab08ffa45efd8",
              "lessThan": "452636ea5410a96e02ebaaf80b21e3620b98e0dd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/aquantia/atlantic/aq_ring.c",
            "drivers/net/ethernet/aquantia/atlantic/aq_ring.h",
            "drivers/net/ethernet/aquantia/atlantic/aq_vec.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.266",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/aquantia/atlantic/aq_ring.c",
            "drivers/net/ethernet/aquantia/atlantic/aq_ring.h",
            "drivers/net/ethernet/aquantia/atlantic/aq_vec.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:35.157",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/307d80193b4a4a75b8dc4e0d3162be3755abbed7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3447641d361dcc5511841d986ad4d849b2900d9b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/452636ea5410a96e02ebaaf80b21e3620b98e0dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4f1c20873f70b4b22ef86dc38dad1fda8e169bcd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a14ceebd13bf857bfca052bc5a6bd49e737912be",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b13202d401e1a20fec89b0cda733dcbaf279f79d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd633280de7fdfd60dc4fcf63d04e2ad95b43269",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free stranded TX buffers on ring deinit\n\naq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean()\ncall, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and\nstops at hw_head, which no longer moves once aq_vec_stop() has stopped\nthe hardware and NAPI. Completed descriptors beyond the budget and\neverything still posted in [hw_head, sw_tail) keep their skb or\nxdp_frame when the interface goes down: aq_vec_ring_free() then frees\nthe buffer ring and the references are lost for good.\n\nToday this is a silent memory leak on every interface down under\nTX/XDP_TX load. With the conversion of the RX path to page_pool posted\nfor net-next it becomes much more visible: XDP_TX frames carry fragment\nreferences on the RX ring's page_pool, so a single stranded frame keeps\nthe pool's inflight count above zero forever. page_pool_destroy() then\nnever completes, the pool is leaked together with its pages, and\n\"page_pool_release_retry() stalled pool shutdown\" is warned every 60\nseconds from that point on, on every ifdown, XDP detach or ring resize\nunder XDP_TX load.\n\nBring back aq_ring_tx_deinit() as it was before the removal and use it\nfor teardown again, with one extension: TX rings can hold xdp_frames\nnowadays, so release those too. They are returned with\nxdp_return_frame() since this runs in process context."
    }
  ],
  "lastModified": "2026-08-23T13:16:47.317",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}