Executive brief
A vulnerability was discovered in the Linux kernel's Broadcom cnic network driver. The issue occurs during the cleanup process when a network device is being removed, where a background task might continue to run after the memory it needs has been deleted. This could lead to a system crash or allow a local attacker to potentially gain unauthorized access or execute malicious code.
Technical details
A use-after-free (UAF) vulnerability exists in the cnic driver (drivers/net/ethernet/broadcom/cnic.c) within the cnic_delete_task function. The root cause is a race condition where cnic_cm_stop_bnx2x_hw() uses cancel_delayed_work() and flush_workqueue(), which fails to guarantee that cyclic delayed work items are fully terminated before cnic_dev is deallocated via cnic_free_dev(). An attacker with local access could exploit this race condition to trigger a UAF when the 'delete_task' callback attempts to dereference the already-freed cnic_dev structure. The fix replaces the asynchronous cancellation with cancel_delayed_work_sync() to ensure all work completes before memory deallocation.
Affected products
- Linux Linux Kernel fdf24086f475 to fde6e73189f4, 7b6a5b0a6b39, 040505593026, e1fcd4a9c09f, 8eeb2091e72d, 6e33a7eed587, 0627e1481676
Timeline
- 2025-09-17: patched: Initial patch authored
- 2025-10-04: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/0405055930264ea8fd26f4131466fa7652e5e47d
- https://git.kernel.org/stable/c/0627e1481676669cae2df0d85b5ff13e7d24c390
- https://git.kernel.org/stable/c/6e33a7eed587062ca8161ad1f4584882a860d697
- https://git.kernel.org/stable/c/7b6a5b0a6b392263c3767fc945b311ea04b34bbd
- https://git.kernel.org/stable/c/8eeb2091e72d75df8ceaa2172638d61b4cf8929a
- https://git.kernel.org/stable/c/cfa7d9b1e3a8604afc84e9e51d789c29574fb216
- https://git.kernel.org/stable/c/e1fcd4a9c09feac0902a65615e866dbf22616125