Executive brief
The Linux kernel's UDP tunnel network interface card (NIC) code contained a race condition in its work queue management. When concurrent device operations occurred, the work queue could be queued twice, leading to a use-after-free vulnerability where freed memory was still being accessed by an active worker thread. This could cause system crashes or instability in systems using UDP tunnel offloading features.
Technical details
This is a use-after-free (UAF) vulnerability in the udp_tunnel_nic_device_sync() function within the Linux kernel's UDP tunnel NIC infrastructure (net/ipv4/udp_tunnel_nic.c). The root cause is a race condition: the workqueue core clears its internal pending bit before invoking the worker, allowing a concurrent thread to queue the work again. When the already-running worker clears the work_pending flag, it mistakenly clears the flag for the newly queued instance. Subsequently, udp_tunnel_nic_unregister() observes work_pending as 0 and frees the structure while the second work item is still active in the queue. The fix prevents redundant work queueing by checking if work_pending is already set before queueing. No authentication or special privileges are required; the vulnerability is triggered through concurrent device operations on systems with UDP tunnel offloading enabled.
Affected products
- Linux Linux Kernel multiple versions with udp_tunnel NIC infrastructure (introduced in 2017, patched 2026-06-25)
Timeline
- 2026-08-15: disclosed: CVE-2026-72405 disclosed
- 2026-06-25: patched: Upstream fix commit ecf69d4b43370c587e48d4d70289dbdb7e039d4d by Eric Dumazet
- 2026-07-24: other: Fix included in stable kernel releases