Executive brief
A vulnerability was identified in the Linux kernel's network bonding driver, specifically within the Adaptive Load Balancing (ALB) mode. This component is responsible for distributing network traffic across multiple physical network interfaces to improve performance and reliability. Under specific conditions—such as rapidly bringing the network connection up and down while receiving certain network messages—the system could crash or experience a service outage due to a memory management error.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel bonding driver's ALB (Adaptive Load Balancing) implementation. The issue occurs in the rlb_arp_recv() function during rapid 'up/down' cycles of the bond interface. Specifically, rlb_deinitialize() can free the rx_hashtbl while RX handlers are still executing, leading to a null pointer dereference or UAF when rlb_arp_recv() attempts to access the table. The vulnerability is triggered by a race condition where recv_probe is accessed after being set to NULL but before concurrent RX processing has finished. The fix involves using WRITE_ONCE to set recv_probe to NULL followed by synchronize_net() to ensure all in-flight RX handlers complete before the hash table is deallocated.
Affected products
- Linux Linux kernel 6.19.0-rc8+; fixed in various stable branches
Timeline
- 2026-02-18: patched: Initial patch submitted by Hangbin Liu
- 2026-05-27: disclosed: CVE-2026-45970 published
References
- https://git.kernel.org/stable/c/c65cdf46ce340c9c00fbbaf84599d2daff43626e
- https://git.kernel.org/stable/c/d31065526f160ee0244a719230aa069daca2bf4d
- https://git.kernel.org/stable/c/db5435b5342e3aaa4521d0f3ccfe94316b253ca1
- https://git.kernel.org/stable/c/de7c097800f07f3c108185c7a38b53a530ba30ff
- https://git.kernel.org/stable/c/e6834a4c474697df23ab9948fd3577b26bf48656
- https://git.kernel.org/stable/c/f94a0de7b9f32745a14a1621c63087a092823587
- https://git.kernel.org/stable/c/fd54ddc929be1d6c3b3b7b35d6d4642a5d9e803c