PT-2026-98551 · Linux · Linux

CVE-2026-97611

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix use-after-free of the flow table mask array
tbl mask array realloc() retires the old mask array before it stops being reachable:
old = ovsl dereference(tbl->mask array);
if (old) {
	...
	call rcu(&old->rcu, mask array rcu cb);
}

rcu assign pointer(tbl->mask array, new);
call rcu() only waits for read-side critical sections already in flight. tbl->mask array still points at old between the call rcu() and the rcu assign pointer(), so a reader entering ovs flow tbl lookup stats() in that window picks up old in a fresh critical section that the pending grace period does not cover.
tbl mask array realloc() runs in process context under ovs mutex, so the window is preemptible and can outlast the grace period. Then mask array rcu cb() frees old before the swap runs:
BUG: KASAN: slab-use-after-free in flow lookup.constprop.0+0x2bf/0x2f0 Read of size 8 at addr ffff888020b3e018 by task poc/741 flow lookup.constprop.0+0x2bf/0x2f0 ovs flow tbl lookup stats+0x4a3/0x5c0 ovs dp process packet+0x19c/0x710 ovs vport receive+0x243/0x390 internal dev xmit+0x81/0x170 Freed by task 728: kfree+0x16a/0x4e0 rcu core+0x853/0x1030
Publish the new array before retiring the old one. The kfree rcu() that call rcu() replaced ran after the swap.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97611

Produtos afetados

Linux