Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74285

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: Stop leased rxq before uninstalling its memory provider<br /> <br /> netif_rxq_cleanup_unlease() tears down the memory provider that was<br /> installed on a physical RX queue through a netkit queue lease. It<br /> currently revokes the provider&amp;#39;s DMA mappings before stopping the<br /> physical queue:<br /> <br /> __netif_mp_uninstall_rxq(virt_rxq, p); /* DMA unmap */<br /> __netif_mp_close_rxq(phys_rxq-&gt;dev, rxq_idx, p); /* queue stop */<br /> <br /> This inverts the ordering used by the regular teardown paths (normal<br /> device unregister and the io_uring zcrx close path), which stop the<br /> queue before revoking the provider&amp;#39;s mappings.<br /> <br /> With the physical queue still live, its NAPI can keep consuming<br /> net_iov entries from the page_pool alloc cache after the<br /> __netif_mp_uninstall_rxq() has already cleared their dma_addr,<br /> opening a window for the device to DMA to a stale or zero address.<br /> <br /> Fix it by swapping the two calls so the queue is stopped (and its<br /> NAPI quiesced) before the provider is uninstalled. No functional<br /> regression was observed across repeated runs of the nk_qlease.py<br /> HW selftest, which exercises the lease teardown path; this was<br /> tested against fbnic QEMU emulation.

Impacto