CVE-2026-80613
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/08/2026
Última modificación:
28/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
veth: fix NAPI leak in XDP enable error path<br />
<br />
During XDP enablement in veth, if xdp_rxq_info_reg() or<br />
xdp_rxq_info_reg_mem_model() fails, the driver rolls back the changes.<br />
<br />
However, the rollback loop:<br />
for (i--; i >= start; i--) {<br />
<br />
decrements the loop index &#39;i&#39; before the first iteration. This<br />
correctly skips unregistering the rxq for the failed index &#39;i&#39; (as<br />
registration failed or was already cleaned up), but it also<br />
erroneously skips calling netif_napi_deli() for rq[i].xdp_napi.<br />
<br />
Since netif_napi_add() was already called for index &#39;i&#39;, this leaves<br />
a dangling napi_struct in the device&#39;s napi_list. When the veth<br />
device is later destroyed, the freed queue memory (which contains the<br />
leaked NAPI structure) can be reused.<br />
<br />
The subsequent device teardown iterates the NAPI list and<br />
corrupts the reallocated memory, leading to UAF.<br />
<br />
Fix this by explicitly deleting the NAPI association for the failed<br />
index &#39;i&#39; before rolling back the successfully configured queues.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/4559770b2a241344d762719e674241fcc8528f02
- https://git.kernel.org/stable/c/4bd2e5dbe62334aae1182d0f0d260f334a49d739
- https://git.kernel.org/stable/c/6739027cb72da26890edd424c77080d187b2a92e
- https://git.kernel.org/stable/c/83090f5e7b54721d71875a6c224d2490b9e73050
- https://git.kernel.org/stable/c/a9e6707322ef215d39d4655b176c094f45f0ab52
- https://git.kernel.org/stable/c/d3eb258ad398cc9402bab3a5e730cd7c5b34efad
- https://git.kernel.org/stable/c/fc51373345e7e6ea73da2650cb497309c50b077a



