« Volver al listado

CVE-2026-90201

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race

This bug was discovered while testing the hns3 driver under channel reconfiguration (`ethtool -L` / `ethtool -G`) with iperf3 traffic on arm64. The race is intermittently triggered when page_pool_destroy() runs page_pool_scrub() concurrently with page return via page_pool_put_netmem() on a different CPU. A WARN in page_pool_clear_pp_info() surfaced the dangling DMA index bits left by the cmpxchg loser, which led to the investigation.

page_pool_scrub() iterates pool->dma_mapped via xa_for_each() with no page ref held. __page_pool_release_netmem_dma() currently reads and writes netmem fields (dma_addr, DMA index bits in pp_magic) after xa_cmpxchg() returns.

Leer descripción completaMostrar menos

The unref path calls put_page() unconditionally regardless of the cmpxchg outcome; when it loses the cmpxchg, it still frees the page before the scrub winner finishes these netmem accesses, so scrub touches a freed page -- a Use-After-Free.

Fix this by splitting the DMA release into two functions:

The scrub path calls __page_pool_unmap_netmem_dma() directly; the return path calls __page_pool_release_netmem_dma().

Detalles técnicos trazas, registros y código del informe original
1. __page_pool_unmap_netmem_dma() caches dma_addr before xa_cmpxchg(),
   does the cmpxchg to remove the DMA mapping, and calls dma_unmap on
   the cached address. It never touches netmem fields after the cmpxchg,
   making it safe for the scrub path which holds no page ref.

2. __page_pool_release_netmem_dma() wraps the above and additionally
   clears dma_addr and DMA index bits in netmem fields. This is safe
   only when the caller holds a page ref, so it is used by the return
   path (page_pool_return_netmem).

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90201",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4f51fb0d257ff4d406ec27966902de075e3b118e",
              "lessThan": "bbfef303f980c1c078b8fa142e10a0e2fbcdd247",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee62ce7a1d909ccba0399680a03c2dee83bcae95",
              "lessThan": "424a9fc4876cc7f28e9cb0aa8d92e920d726e350",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee62ce7a1d909ccba0399680a03c2dee83bcae95",
              "lessThan": "9b65b0253ad5a66f73efee9a79a21a1e2b57cf59",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ee62ce7a1d909ccba0399680a03c2dee83bcae95",
              "lessThan": "24ef02f934eeb48830cff6b739abc3c62b1d107b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c30ae60f41f9edd6e1b5cad41cf28ce04dae39e4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.34",
              "lessThan": "6.12.110",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.3",
              "lessThan": "6.16",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/core/page_pool.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/core/page_pool.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:15.053",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/24ef02f934eeb48830cff6b739abc3c62b1d107b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/424a9fc4876cc7f28e9cb0aa8d92e920d726e350",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b65b0253ad5a66f73efee9a79a21a1e2b57cf59",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bbfef303f980c1c078b8fa142e10a0e2fbcdd247",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race\n\nThis bug was discovered while testing the hns3 driver under channel\nreconfiguration (`ethtool -L` / `ethtool -G`) with iperf3 traffic on\narm64. The race is intermittently triggered when page_pool_destroy()\nruns page_pool_scrub() concurrently with page return via\npage_pool_put_netmem() on a different CPU. A WARN in\npage_pool_clear_pp_info() surfaced the dangling DMA index bits left\nby the cmpxchg loser, which led to the investigation.\n\npage_pool_scrub() iterates pool->dma_mapped via xa_for_each() with no\npage ref held. __page_pool_release_netmem_dma() currently reads and\nwrites netmem fields (dma_addr, DMA index bits in pp_magic) after\nxa_cmpxchg() returns. The unref path calls put_page() unconditionally\nregardless of the cmpxchg outcome; when it loses the cmpxchg, it still\nfrees the page before the scrub winner finishes these netmem accesses,\nso scrub touches a freed page -- a Use-After-Free.\n\nFix this by splitting the DMA release into two functions:\n\n1. __page_pool_unmap_netmem_dma() caches dma_addr before xa_cmpxchg(),\n   does the cmpxchg to remove the DMA mapping, and calls dma_unmap on\n   the cached address. It never touches netmem fields after the cmpxchg,\n   making it safe for the scrub path which holds no page ref.\n\n2. __page_pool_release_netmem_dma() wraps the above and additionally\n   clears dma_addr and DMA index bits in netmem fields. This is safe\n   only when the caller holds a page ref, so it is used by the return\n   path (page_pool_return_netmem).\n\nThe scrub path calls __page_pool_unmap_netmem_dma() directly; the return\npath calls __page_pool_release_netmem_dma()."
    }
  ],
  "lastModified": "2026-09-17T17:17:15.053",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}