« Volver al listado

CVE-2026-98286

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown

In drop_monitor teardown paths (net_dm_trace_off_set(), net_dm_hw_monitor_stop(), and error unwind paths in net_dm_trace_on_set() and net_dm_hw_monitor_start()), per-CPU timers are stopped using timer_delete_sync() followed by cancel_work_sync().

However, there is a circular dependency between send_timer and dm_alert_work: 1) sched_send_work() (timer callback) schedules dm_alert_work.

Leer descripción completaMostrar menos

2) send_dm_alert() / net_dm_hw_summary_work() calls reset_per_cpu_data() or net_dm_hw_reset_per_cpu_data(). 3) If memory allocation fails under memory pressure in the reset function, it re-arms the timer via mod_timer(&data->send_timer, ...).

If dm_alert_work is running concurrently while timer_delete_sync() executes on another CPU, an allocation failure in the worker will re-arm the timer after timer_delete_sync() has already returned. Once cancel_work_sync() completes and module_put() is called, the timer remains active in the timer wheel. If the module is then unloaded, the timer will fire and execute sched_send_work() in freed memory, triggering a kernel panic / use-after-free.

Switch from timer_delete_sync() to timer_shutdown_sync(). This guarantees that any in-flight timer handler has finished and prevents subsequent re-arming attempts from running workers from succeeding. When monitoring is restarted later, timer_setup() is invoked, which cleanly re-initializes the timer.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98286",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9398e9c0b1d44eeb700e9e766c02bcc765c82570",
              "lessThan": "9616b0c67fbd8cc0b49de7b26cdf2ab33747c80e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9398e9c0b1d44eeb700e9e766c02bcc765c82570",
              "lessThan": "bda4d9525fb91a2388ee09669421b8d505290864",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9398e9c0b1d44eeb700e9e766c02bcc765c82570",
              "lessThan": "c391a40f71886b28c082b47270f0e856fa3e1150",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2514c7ad115e762562c7bdd58bb1ab3425a98245",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "439b1164da3612ec7e186e1dc314471e7190bfc7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.27",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.11.11",
              "lessThan": "5.12",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/core/drop_monitor.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/core/drop_monitor.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:18.740",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/9616b0c67fbd8cc0b49de7b26cdf2ab33747c80e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bda4d9525fb91a2388ee09669421b8d505290864",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c391a40f71886b28c082b47270f0e856fa3e1150",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown\n\nIn drop_monitor teardown paths (net_dm_trace_off_set(),\nnet_dm_hw_monitor_stop(), and error unwind paths in net_dm_trace_on_set()\nand net_dm_hw_monitor_start()), per-CPU timers are stopped using\ntimer_delete_sync() followed by cancel_work_sync().\n\nHowever, there is a circular dependency between send_timer and\ndm_alert_work:\n1) sched_send_work() (timer callback) schedules dm_alert_work.\n2) send_dm_alert() / net_dm_hw_summary_work() calls reset_per_cpu_data()\n   or net_dm_hw_reset_per_cpu_data().\n3) If memory allocation fails under memory pressure in the reset\n   function, it re-arms the timer via mod_timer(&data->send_timer, ...).\n\nIf dm_alert_work is running concurrently while timer_delete_sync()\nexecutes on another CPU, an allocation failure in the worker will\nre-arm the timer after timer_delete_sync() has already returned.\nOnce cancel_work_sync() completes and module_put() is called, the timer\nremains active in the timer wheel. If the module is then unloaded, the\ntimer will fire and execute sched_send_work() in freed memory,\ntriggering a kernel panic / use-after-free.\n\nSwitch from timer_delete_sync() to timer_shutdown_sync(). This guarantees\nthat any in-flight timer handler has finished and prevents subsequent\nre-arming attempts from running workers from succeeding. When monitoring\nis restarted later, timer_setup() is invoked, which cleanly\nre-initializes the timer."
    }
  ],
  "lastModified": "2026-10-06T09:18:18.740",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}