« Volver al listado

CVE-2026-90232

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

amt: Don't support cross-netns setup.

When a lower device is unregistered, amt_device_event() tries to unregister its upper AMT device, but it has two problems.

If AMT device is created on a lower device in another netns, removing the lower device triggers the splat below and gets stuck until all upper devices are removed. [0]

The cross-netns setup seems unintentional considering 1. and the following points:

Instead of supporting it properly and preparing for per-netns netdev unreg, let's forbid cross-netns setup.

Note that the problem 2. needs a separate fix.

Detalles técnicos trazas, registros y código del informe original
  1. amt_lookup_upper_dev() looks up an upper device in the
      lower device's netns only

  2. amt_device_event() unregisters a single upper device only

  * amt_link_setup() sets dev->netns_immutable to true
  * skb_scrub_packet() is not called in the fast path
  * iproute2 binary fails to find cross-netns lower device via
    link-netns:
      # ip -n ns1 link add amt0 link-netns ns2 type amt dev veth1
      Cannot find device "veth1"

[0]:
WARNING: net/core/dev.c:12518 at unregister_netdevice_many_notify+0x1cce/0x2250, CPU#48: ip/2031
Modules linked in:
CPU: 48 UID: 0 PID: 2031 Comm: ip Not tainted 7.2.0-rc5+ #27 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
RIP: 0010:unregister_netdevice_many_notify (net/core/dev.c:12518)
Code: 89 ef e8 d5 52 ae fe e9 d0 f4 ff ff 48 8d 3d f9 3b 9c 02 48 c7 c6 c0 0b 63 84 ba ab 1f 00 00 67 48 0f b9 3a e9 65 ff ff ff 90 <0f> 0b 90 eb 81 48 8d 3d f6 3b 9c 02 48 c7 c6 c0 0b 63 84 ba e2 1f
RSP: 0018:ffffc90004abf160 EFLAGS: 00010212
RAX: ffff888104d38260 RBX: ffff88800b0911b8 RCX: dffffc0000000000
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff85b9f880
RBP: ffffc90004abf2d0 R08: ffffffff85b9f887 R09: 1ffffffff0b73f10
R10: dffffc0000000000 R11: fffffbfff0b73f11 R12: ffff88800b091d08
R13: ffff88800b091178 R14: dffffc0000000000 R15: ffff88800b091000
FS:  00007f555b86c600(0000) GS:ffff8881942a0000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000562107d489c0 CR3: 0000000109a40002 CR4: 0000000000372ef0
Call Trace:
 <TASK>
 rtnl_dellink (net/core/rtnetlink.c:3632 net/core/rtnetlink.c:3674)
 rtnetlink_rcv_msg (net/core/rtnetlink.c:7112)
 netlink_rcv_skb (net/netlink/af_netlink.c:2556)
 netlink_unicast (net/netlink/af_netlink.c:1319)
 netlink_sendmsg (net/netlink/af_netlink.c:1900)
 ____sys_sendmsg (net/socket.c:775)
 __sys_sendmsg (net/socket.c:2738)
 do_syscall_64 (arch/x86/entry/syscall_64.c:63)
 entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
...
unregister_netdevice: waiting for veth0 to become free. Usage count = 7
ref_tracker: netdev@ffff88800d7496d8 has 3/3 users at
     __netdev_adjacent_dev_insert (./include/linux/netdevice.h:4525 ./include/linux/netdevice.h:4554 net/core/dev.c:8791)
     __netdev_upper_dev_link (net/core/dev.c:8879 net/core/dev.c:8963)
     netdev_upper_dev_link (net/core/dev.c:9009)
     amt_newlink (drivers/net/amt.c:3321)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90232",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b9022b53adad88fd6cf2b9718c9e498504f3e1dd",
              "lessThan": "569eb11f0990849ba48706a2bfa743273707e254",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b9022b53adad88fd6cf2b9718c9e498504f3e1dd",
              "lessThan": "e1dc0af719a2566ae7ccb82c0a11f70aa54908e9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b9022b53adad88fd6cf2b9718c9e498504f3e1dd",
              "lessThan": "e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/amt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/amt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:19.043",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/569eb11f0990849ba48706a2bfa743273707e254",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1dc0af719a2566ae7ccb82c0a11f70aa54908e9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: Don't support cross-netns setup.\n\nWhen a lower device is unregistered, amt_device_event() tries\nto unregister its upper AMT device, but it has two problems.\n\n  1. amt_lookup_upper_dev() looks up an upper device in the\n      lower device's netns only\n\n  2. amt_device_event() unregisters a single upper device only\n\nIf AMT device is created on a lower device in another netns,\nremoving the lower device triggers the splat below and gets\nstuck until all upper devices are removed. [0]\n\nThe cross-netns setup seems unintentional considering 1. and\nthe following points:\n\n  * amt_link_setup() sets dev->netns_immutable to true\n  * skb_scrub_packet() is not called in the fast path\n  * iproute2 binary fails to find cross-netns lower device via\n    link-netns:\n      # ip -n ns1 link add amt0 link-netns ns2 type amt dev veth1\n      Cannot find device \"veth1\"\n\nInstead of supporting it properly and preparing for per-netns\nnetdev unreg, let's forbid cross-netns setup.\n\nNote that the problem 2. needs a separate fix.\n\n[0]:\nWARNING: net/core/dev.c:12518 at unregister_netdevice_many_notify+0x1cce/0x2250, CPU#48: ip/2031\nModules linked in:\nCPU: 48 UID: 0 PID: 2031 Comm: ip Not tainted 7.2.0-rc5+ #27 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nRIP: 0010:unregister_netdevice_many_notify (net/core/dev.c:12518)\nCode: 89 ef e8 d5 52 ae fe e9 d0 f4 ff ff 48 8d 3d f9 3b 9c 02 48 c7 c6 c0 0b 63 84 ba ab 1f 00 00 67 48 0f b9 3a e9 65 ff ff ff 90 <0f> 0b 90 eb 81 48 8d 3d f6 3b 9c 02 48 c7 c6 c0 0b 63 84 ba e2 1f\nRSP: 0018:ffffc90004abf160 EFLAGS: 00010212\nRAX: ffff888104d38260 RBX: ffff88800b0911b8 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff85b9f880\nRBP: ffffc90004abf2d0 R08: ffffffff85b9f887 R09: 1ffffffff0b73f10\nR10: dffffc0000000000 R11: fffffbfff0b73f11 R12: ffff88800b091d08\nR13: ffff88800b091178 R14: dffffc0000000000 R15: ffff88800b091000\nFS:  00007f555b86c600(0000) GS:ffff8881942a0000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000562107d489c0 CR3: 0000000109a40002 CR4: 0000000000372ef0\nCall Trace:\n <TASK>\n rtnl_dellink (net/core/rtnetlink.c:3632 net/core/rtnetlink.c:3674)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7112)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1319)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n ____sys_sendmsg (net/socket.c:775)\n __sys_sendmsg (net/socket.c:2738)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n...\nunregister_netdevice: waiting for veth0 to become free. Usage count = 7\nref_tracker: netdev@ffff88800d7496d8 has 3/3 users at\n     __netdev_adjacent_dev_insert (./include/linux/netdevice.h:4525 ./include/linux/netdevice.h:4554 net/core/dev.c:8791)\n     __netdev_upper_dev_link (net/core/dev.c:8879 net/core/dev.c:8963)\n     netdev_upper_dev_link (net/core/dev.c:9009)\n     amt_newlink (drivers/net/amt.c:3321)"
    }
  ],
  "lastModified": "2026-09-17T17:17:19.043",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}