Executive brief
A vulnerability in the Linux kernel's Microsoft Azure Network Adapter (MANA) driver could cause a system crash. This occurs when the system attempts to reset a network port that is already in a partially disconnected state, leading to a 'NULL pointer dereference.' In practice, this could allow a local user or a malfunctioning system process to trigger a kernel panic, resulting in a complete service outage for the affected machine.
Technical details
A vulnerability exists in the Microsoft Azure Network Adapter (MANA) Ethernet driver (mana_en.c) within the Linux kernel. The issue occurs in the mana_detach() function when it is called on a port that is already in a detached state—specifically after a previous detach succeeded but a subsequent attach failed. In this state, transmit and receive queue structures (apc->tx_qp and apc->rxqs) have already been freed. Unconditionally executing mana_detach() again leads to a NULL pointer dereference during queue teardown. The fix introduces an early exit in mana_detach() if the device is not present, ensuring the function is idempotent. This prevents kernel panics during queue reset work or recovery paths.
Affected products
- Linux Linux Kernel 6.18.33 - 6.18.35, 7.0 - 7.0.12
Timeline
- 2026-05-25: patched: Initial fix commit authored
- 2026-07-19: disclosed: CVE published