Description
In the Linux kernel, the following vulnerability has been resolved:

net: mana: Sync page pool RX frags for CPU

MANA allocates RX buffers from page pool fragments when frag_count is
greater than 1. In that case the buffers remain DMA mapped by page pool
and the RX completion path does not call dma_unmap_single(). As a result,
the implicit sync-for-CPU normally performed by dma_unmap_single() is
missing before the packet data is passed to the networking stack.

This breaks RX on configurations which require explicit DMA syncing, for
example when booted with swiotlb=force.

Fix this by recording the page pool page and DMA sync offset when the RX
buffer is allocated, and syncing the received packet range for CPU access
before handing the RX buffer to the stack.
Published: 2026-08-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MANA networking driver in the Linux kernel does not perform the necessary DMA synchronization when allocating receive buffers made of multiple fragments. When fragment count exceeds one, the driver keeps the buffers mapped but never calls dma_unmap_single during the RX completion path, skipping the implicit CPU synchronization that normally makes freshly received packet data visible. The result is that corrupted or stale packet data can be handed to the networking stack, potentially causing kernel instability and crashes.

Affected Systems

All distributions that ship a Linux kernel with MANA support and that have not yet incorporated commit bc650dd5. Because the flaw manifests only when a packet is received under a configuration that forces explicit DMA sync (for example with the swiotlb=force boot parameter), any system running a kernel predating that commit on such a configuration is affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability, yet the EPSS score is less than 1% and it is not listed in the CISA KEV catalog, suggesting low observed exploitation. Based on the description, it is inferred that an attacker with network access could send crafted traffic that triggers the missing sync, leading to kernel Oops or panic and a denial‑of‑service condition. The likely attack vector would be a remote attacker sending specific packets to a device configured with swiotlb=force or other explicit DMA syncing requirements.

Generated by OpenCVE AI on August 18, 2026 at 05:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes commit bc650dd5 or later.
  • If a kernel upgrade is not possible, remove or disable the swiotlb=force boot parameter to avoid the configuration that triggers the missing DMA sync.
  • Monitor kernel logs for Oops, BUG, or DMA sync related messages and take action if such events are observed.

Generated by OpenCVE AI on August 18, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-823

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-820
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-823

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MANA allocates RX buffers from page pool fragments when frag_count is greater than 1. In that case the buffers remain DMA mapped by page pool and the RX completion path does not call dma_unmap_single(). As a result, the implicit sync-for-CPU normally performed by dma_unmap_single() is missing before the packet data is passed to the networking stack. This breaks RX on configurations which require explicit DMA syncing, for example when booted with swiotlb=force. Fix this by recording the page pool page and DMA sync offset when the RX buffer is allocated, and syncing the received packet range for CPU access before handing the RX buffer to the stack.
Title net: mana: Sync page pool RX frags for CPU
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:39:55.896Z

Reserved: 2026-08-09T03:40:39.903Z

Link: CVE-2026-72064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:16.003

Modified: 2026-08-17T06:18:04.810

Link: CVE-2026-72064

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72064 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T06:00:04Z

Weaknesses