Executive brief
A vulnerability was found in the Linux kernel's networking subsystem that could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory while recycling network data buffers, leading to a 'use-after-free' condition. This could impact system stability and the security of data being processed by the network stack.
Technical details
A use-after-free (UAF) vulnerability exists in net/core/page_pool.c within the page_pool_recycle_in_ring function. The root cause is a race condition where a page_pool object can be freed while it is still attempting to recycle the last page in its ring buffer. Specifically, the page_pool_release process can proceed to destroy the pool while a producer is still holding a lock or accessing the ring structure. An attacker with local access could exploit this to trigger a kernel crash or achieve arbitrary code execution. The fix introduces a producer-lock barrier in page_pool_release to ensure all recycling operations are complete before the pool is destroyed.
Affected products
- Linux Linux kernel 4.18 to 6.13-rc3
Timeline
- 2025-05-27: patched: Initial patch submitted by Dong Chenchen
- 2025-07-03: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1a8c0b61d4cb55c5440583ec9e7f86a730369e32
- https://git.kernel.org/stable/c/271683bb2cf32e5126c592b5d5e6a756fa374fd9
- https://git.kernel.org/stable/c/4914c0a166540e534a0c1d43affd329d95fb56fd
- https://git.kernel.org/stable/c/4ab8c0f8905c9c4d05e7f437e65a9a365573ff02
- https://git.kernel.org/stable/c/c2c906142293931e33ef4be79ebc36c25c4e21dd
- https://git.kernel.org/stable/c/d69f28ef7cdafdcf37ee310f38b1399e7d05f9a8
- https://git.kernel.org/stable/c/e869a85acc2e60dc554579b910826a4919d8cd98