Description
In the Linux kernel, the following vulnerability has been resolved:

net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()

sashiko is reporting that trying to read /sys/kernel/debug/ref_tracker/*
causes use-afer-free crash when either alloc_percpu() or dev_addr_init()
in alloc_netdev_mqs() failed, for commit 4d92b95ff2f9 ("net: add net device
refcount tracker infrastructure") added ref_tracker_dir_exit() to only
free_netdev() path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free crash leading to kernel panic (Denial of Service)
Action: Apply patch
AI Analysis

Impact

A missing cleanup routine in the Linux kernel’s network device allocation path leaves a reference tracker directory unfreed when the allocation of per‑CPU data or the initialization of a device address fails. Accessing the /sys/kernel/debug/ref_tracker/* interface at that point triggers a use‑after‑free crash, causing a kernel panic. The vulnerability does not provide direct code execution or data exfiltration, but it can be leveraged to disrupt system availability by bringing the kernel down.

Affected Systems

All Linux kernel releases prior to the fix for commit 4d92b95ff2f9 are affected. The issue was introduced by the refcount tracker infrastructure added in that commit and applies to any build that includes the network device allocation function alloc_netdev_mqs(). Vendor‑specific version information is not supplied in the CVE data, so administrators should assume all affected kernel versions require remediation.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the vulnerable kernel (or remote if the debug filesystem is exposed), and the impact is limited to a denial of service rather than privilege escalation. Given the limited attack surface and low exploitation likelihood, the overall risk is moderate, but the potential for a system crash means it should be treated as a high severity issue within an incident response context.

Generated by OpenCVE AI on September 18, 2026 at 22:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds the missing ref_tracker_dir_exit() cleanup in alloc_netdev_mqs()
  • If possible, disable or unmount the sysfs debugfs interface to prevent access to /sys/kernel/debug/ref_tracker/
  • Reboot the system following patch installation to ensure all stale references are cleared

Generated by OpenCVE AI on September 18, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() sashiko is reporting that trying to read /sys/kernel/debug/ref_tracker/* causes use-afer-free crash when either alloc_percpu() or dev_addr_init() in alloc_netdev_mqs() failed, for commit 4d92b95ff2f9 ("net: add net device refcount tracker infrastructure") added ref_tracker_dir_exit() to only free_netdev() path.
Title net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:34.543Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:06.053

Modified: 2026-09-17T17:17:06.053

Link: CVE-2026-90135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:30:15Z

Weaknesses