Description
In the Linux kernel, the following vulnerability has been resolved:

netdevsim: update queue NAPI association on queue reset

In netdevsim, receive queues (struct nsim_rq) embed their own struct
napi_struct. When queue reset is performed (e.g. via queue_reset
debugfs), nsim_queue_start() swaps in a newly allocated struct nsim_rq,
and nsim_queue_mem_free() later deletes and frees the old one.

However, nsim_queue_start() failed to update the queue-to-NAPI mapping
via netif_queue_set_napi(). As a result, dev->_rx[idx].napi continued to
point to the old NAPI struct. After the old queue was freed, a subsequent
queue dump via Netlink (NETDEV_CMD_QUEUE_GET) triggered a KASAN
slab-use-after-free read in nla_put_napi_id() when accessing
rxq->napi->napi_id.

Fix this by calling netif_queue_set_napi() in nsim_queue_start() to
associate the new NAPI with the RX queue, and clear the association
with netif_queue_set_napi(..., NULL) in nsim_del_napi() during teardown.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel memory corruption
Action: Apply patch
AI Analysis

Impact

A flaw in the Linux kernel's netdevsim implementation caused a use‑after‑free in the NAPI subsystem. When a queue reset operation swapped in a new queue structure without updating the kernel’s internal queue‑to‑NAPI mapping, the old NAPI pointer remained in the device’s receive queue array. After the old structure was freed, a subsequent queue inspection via Netlink attempted to read the NAPI identifier, triggering the Kernel Address Sanitizer and exposing the stale pointer. The result is a kernel crash rather than arbitrary code execution, but the crash can be forced by an attacker who can reset queues or request queue dumps, leading to a denial‑of‑service of the affected system.

Affected Systems

The vulnerability exists in all kernel builds that contain the netdevsim driver. It affects Linux kernel releases prior to the introduction of the fix, which can be identified by the absence of the netif_queue_set_napi() call in nsim_queue_start(). No specific version numbers were supplied, so all legacy kernel installations lacking this patch are vulnerable.

Risk and Exploitability

The CVSS score is not provided, but the EPSS score remains below 1 %, indicating a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Because the vulnerability requires the attacker to perform a queue reset and then request a queue dump, it is an in‑kernel use‑after‑free that results in a crash. While the attack vector is local and requires sufficient privileges to manipulate queue state, the compounded impact remains denial of service rather than privilege escalation or data exfiltration.

Generated by OpenCVE AI on September 18, 2026 at 23:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel release that includes the netdevsim NAPI association fix
  • Configure the system to restrict queue reset and queue dump operations to privileged users only
  • If upgrading is not immediately possible, disable the netdevsim driver or monitor kernel logs for KASAN activity and apply a local patch if available

Generated by OpenCVE AI on September 18, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netdevsim: update queue NAPI association on queue reset In netdevsim, receive queues (struct nsim_rq) embed their own struct napi_struct. When queue reset is performed (e.g. via queue_reset debugfs), nsim_queue_start() swaps in a newly allocated struct nsim_rq, and nsim_queue_mem_free() later deletes and frees the old one. However, nsim_queue_start() failed to update the queue-to-NAPI mapping via netif_queue_set_napi(). As a result, dev->_rx[idx].napi continued to point to the old NAPI struct. After the old queue was freed, a subsequent queue dump via Netlink (NETDEV_CMD_QUEUE_GET) triggered a KASAN slab-use-after-free read in nla_put_napi_id() when accessing rxq->napi->napi_id. Fix this by calling netif_queue_set_napi() in nsim_queue_start() to associate the new NAPI with the RX queue, and clear the association with netif_queue_set_napi(..., NULL) in nsim_del_napi() during teardown.
Title netdevsim: update queue NAPI association on queue reset
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:20.070Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:03.367

Modified: 2026-09-17T17:17:03.367

Link: CVE-2026-90113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:00:12Z

Weaknesses