PT-2026-98551 · Linux · Linux
CVE-2026-97611
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix use-after-free of the flow table mask array
tbl mask array realloc() retires the old mask array before it stops being
reachable:
old = ovsl dereference(tbl->mask array);
if (old) {
...
call rcu(&old->rcu, mask array rcu cb);
}
rcu assign pointer(tbl->mask array, new);call rcu() only waits for read-side critical sections already in flight.
tbl->mask array still points at old between the call rcu() and the
rcu assign pointer(), so a reader entering ovs flow tbl lookup stats() in
that window picks up old in a fresh critical section that the pending
grace period does not cover.
tbl mask array realloc() runs in process context under ovs mutex, so the
window is preemptible and can outlast the grace period. Then
mask array rcu cb() frees old before the swap runs:
BUG: KASAN: slab-use-after-free in flow lookup.constprop.0+0x2bf/0x2f0
Read of size 8 at addr ffff888020b3e018 by task poc/741
flow lookup.constprop.0+0x2bf/0x2f0
ovs flow tbl lookup stats+0x4a3/0x5c0
ovs dp process packet+0x19c/0x710
ovs vport receive+0x243/0x390
internal dev xmit+0x81/0x170
Freed by task 728:
kfree+0x16a/0x4e0
rcu core+0x853/0x1030
Publish the new array before retiring the old one. The kfree rcu() that
call rcu() replaced ran after the swap.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux