CVE-2026-74285
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: Stop leased rxq before uninstalling its memory provider<br />
<br />
netif_rxq_cleanup_unlease() tears down the memory provider that was<br />
installed on a physical RX queue through a netkit queue lease. It<br />
currently revokes the provider&#39;s DMA mappings before stopping the<br />
physical queue:<br />
<br />
__netif_mp_uninstall_rxq(virt_rxq, p); /* DMA unmap */<br />
__netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p); /* queue stop */<br />
<br />
This inverts the ordering used by the regular teardown paths (normal<br />
device unregister and the io_uring zcrx close path), which stop the<br />
queue before revoking the provider&#39;s mappings.<br />
<br />
With the physical queue still live, its NAPI can keep consuming<br />
net_iov entries from the page_pool alloc cache after the<br />
__netif_mp_uninstall_rxq() has already cleared their dma_addr,<br />
opening a window for the device to DMA to a stale or zero address.<br />
<br />
Fix it by swapping the two calls so the queue is stopped (and its<br />
NAPI quiesced) before the provider is uninstalled. No functional<br />
regression was observed across repeated runs of the nk_qlease.py<br />
HW selftest, which exercises the lease teardown path; this was<br />
tested against fbnic QEMU emulation.



