CVE-2026-80613
In the Linux kernel, the following vulnerability has been resolved:
veth: fix NAPI leak in XDP enable error path
During XDP enablement in veth, if xdp_rxq_info_reg() or xdp_rxq_info_reg_mem_model() fails, the driver rolls back the changes.
decrements the loop index 'i' before the first iteration. This correctly skips unregistering the rxq for the failed index 'i' (as registration failed or was already cleaned up), but it also erroneously skips calling netif_napi_deli() for rq[i].xdp_napi.
Since netif_napi_add() was already called for index 'i', this leaves a dangling napi_struct in the device's napi_list. When the veth device is later destroyed, the freed queue memory (which contains the leaked NAPI structure) can be reused.
Leer descripción completaMostrar menos
The subsequent device teardown iterates the NAPI list and corrupts the reallocated memory, leading to UAF.
Fix this by explicitly deleting the NAPI association for the failed index 'i' before rolling back the successfully configured queues.
Detalles técnicos trazas, registros y código del informe original
However, the rollback loop:
for (i--; i >= start; i--) {CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact60 %
Vulnerabilidad local (AV:L/PR:L) en kernel Linux permite escalada de privilegios (C:H/I:H/A:H) explotando fuga de NAPI y use-after-free. T1499.004 por DoS potencial al corromper memoria de dispositivo; T1565.001 por modificación de datos de kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/4559770b2a241344d762719e674241fcc8528f02
- https://git.kernel.org/stable/c/4bd2e5dbe62334aae1182d0f0d260f334a49d739
- https://git.kernel.org/stable/c/6739027cb72da26890edd424c77080d187b2a92e
- https://git.kernel.org/stable/c/83090f5e7b54721d71875a6c224d2490b9e73050
- https://git.kernel.org/stable/c/a9e6707322ef215d39d4655b176c094f45f0ab52
- https://git.kernel.org/stable/c/d3eb258ad398cc9402bab3a5e730cd7c5b34efad
- https://git.kernel.org/stable/c/fc51373345e7e6ea73da2650cb497309c50b077a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80613",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "fc51373345e7e6ea73da2650cb497309c50b077a",
"versionType": "git"
},
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "4559770b2a241344d762719e674241fcc8528f02",
"versionType": "git"
},
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "83090f5e7b54721d71875a6c224d2490b9e73050",
"versionType": "git"
},
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "d3eb258ad398cc9402bab3a5e730cd7c5b34efad",
"versionType": "git"
},
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "a9e6707322ef215d39d4655b176c094f45f0ab52",
"versionType": "git"
},
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "4bd2e5dbe62334aae1182d0f0d260f334a49d739",
"versionType": "git"
},
{
"status": "affected",
"version": "b02e5a0ebb172c8276cea3151942aac681f7a4a6",
"lessThan": "6739027cb72da26890edd424c77080d187b2a92e",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/veth.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/veth.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-28T08:16:45.303",
"references": [
{
"url": "https://git.kernel.org/stable/c/4559770b2a241344d762719e674241fcc8528f02",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4bd2e5dbe62334aae1182d0f0d260f334a49d739",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6739027cb72da26890edd424c77080d187b2a92e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/83090f5e7b54721d71875a6c224d2490b9e73050",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9e6707322ef215d39d4655b176c094f45f0ab52",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d3eb258ad398cc9402bab3a5e730cd7c5b34efad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fc51373345e7e6ea73da2650cb497309c50b077a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix NAPI leak in XDP enable error path\n\nDuring XDP enablement in veth, if xdp_rxq_info_reg() or\nxdp_rxq_info_reg_mem_model() fails, the driver rolls back the changes.\n\nHowever, the rollback loop:\n\tfor (i--; i >= start; i--) {\n\ndecrements the loop index 'i' before the first iteration. This\ncorrectly skips unregistering the rxq for the failed index 'i' (as\nregistration failed or was already cleaned up), but it also\nerroneously skips calling netif_napi_deli() for rq[i].xdp_napi.\n\nSince netif_napi_add() was already called for index 'i', this leaves\na dangling napi_struct in the device's napi_list. When the veth\ndevice is later destroyed, the freed queue memory (which contains the\nleaked NAPI structure) can be reused.\n\nThe subsequent device teardown iterates the NAPI list and\ncorrupts the reallocated memory, leading to UAF.\n\nFix this by explicitly deleting the NAPI association for the failed\nindex 'i' before rolling back the successfully configured queues."
}
],
"lastModified": "2026-08-29T07:16:46.123",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}