Executive brief
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem could allow a local user to cause a system crash. The issue occurs when the system tries to access network information for certain hardware-offloaded programs while that network section is being deleted. This race condition leads to a 'use-after-free' error, which typically results in a kernel panic or system instability.
Technical details
A use-after-free vulnerability exists in kernel/bpf/offload.c within the bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() functions. The root cause is the use of get_net() on a network namespace (netns) whose reference count may have already reached zero during teardown. While rtnl_lock and bpf_devs_lock protect the netdev pointer, they do not prevent the underlying netns refcount from hitting zero, leading to a refcount_t increment on zero. An attacker with local access could potentially trigger this race condition to cause a kernel oops or denial of service. The fix replaces get_net() with maybe_get_net(), which safely handles zeroed reference counts by returning NULL.
Affected products
- Linux Linux 4.16 to 7.0.10
Timeline
- 2026-04-09: patched: Initial fix commit a0c584fc18056709c8e047a82a6045d6c209f4ce
- 2026-06-24: disclosed: CVE published