Description
In the Linux kernel, the following vulnerability has been resolved:

net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race

This bug was discovered while testing the hns3 driver under channel
reconfiguration (`ethtool -L` / `ethtool -G`) with iperf3 traffic on
arm64. The race is intermittently triggered when page_pool_destroy()
runs page_pool_scrub() concurrently with page return via
page_pool_put_netmem() on a different CPU. A WARN in
page_pool_clear_pp_info() surfaced the dangling DMA index bits left
by the cmpxchg loser, which led to the investigation.

page_pool_scrub() iterates pool->dma_mapped via xa_for_each() with no
page ref held. __page_pool_release_netmem_dma() currently reads and
writes netmem fields (dma_addr, DMA index bits in pp_magic) after
xa_cmpxchg() returns. The unref path calls put_page() unconditionally
regardless of the cmpxchg outcome; when it loses the cmpxchg, it still
frees the page before the scrub winner finishes these netmem accesses,
so scrub touches a freed page -- a Use-After-Free.

Fix this by splitting the DMA release into two functions:

1. __page_pool_unmap_netmem_dma() caches dma_addr before xa_cmpxchg(),
does the cmpxchg to remove the DMA mapping, and calls dma_unmap on
the cached address. It never touches netmem fields after the cmpxchg,
making it safe for the scrub path which holds no page ref.

2. __page_pool_release_netmem_dma() wraps the above and additionally
clears dma_addr and DMA index bits in netmem fields. This is safe
only when the caller holds a page ref, so it is used by the return
path (page_pool_return_netmem).

The scrub path calls __page_pool_unmap_netmem_dma() directly; the return
path calls __page_pool_release_netmem_dma().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: kernel memory corruption via use‑after‑free
Action: Patch Now
AI Analysis

Impact

A race condition exists between page_pool_scrub() and page_pool_put_netmem(), which can cause the kernel to free a page that is still being processed; this use‑after‑free results in corruption of kernel memory and can be leveraged by an attacker with local or privileged access to achieve arbitrary code execution or cause a kernel crash.

Affected Systems

All Linux kernel installations that have not applied the commit identified by 24ef02f9 (or an equivalent upstream patch) are affected. The vulnerability was discovered during operation of the hns3 driver on arm64, but the flaw is present in the generic page_pool implementation and therefore applies to any kernel version lacking the fix, regardless of distribution or specific version number.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. Exploitation would require an attacker to be able to trigger channel reconfiguration while network traffic is active, which generally implies local or privileged access. If successfully exploited, kernel memory corruption could lead to privilege escalation or a denial‑of‑service via kernel crash.

Generated by OpenCVE AI on September 20, 2026 at 03:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a build that includes commit 24ef02f9 or later, which separates DMA release into __page_pool_unmap_netmem_dma and __page_pool_release_netmem_dma.
  • If a kernel update is not immediately possible, manually apply the patch that implements the split DMA release functions to eliminate the race condition.
  • Avoid performing network channel reconfiguration during active traffic; if the hns3 driver is non‑essential, consider disabling it until the kernel patch is available.

Generated by OpenCVE AI on September 20, 2026 at 03:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race This bug was discovered while testing the hns3 driver under channel reconfiguration (`ethtool -L` / `ethtool -G`) with iperf3 traffic on arm64. The race is intermittently triggered when page_pool_destroy() runs page_pool_scrub() concurrently with page return via page_pool_put_netmem() on a different CPU. A WARN in page_pool_clear_pp_info() surfaced the dangling DMA index bits left by the cmpxchg loser, which led to the investigation. page_pool_scrub() iterates pool->dma_mapped via xa_for_each() with no page ref held. __page_pool_release_netmem_dma() currently reads and writes netmem fields (dma_addr, DMA index bits in pp_magic) after xa_cmpxchg() returns. The unref path calls put_page() unconditionally regardless of the cmpxchg outcome; when it loses the cmpxchg, it still frees the page before the scrub winner finishes these netmem accesses, so scrub touches a freed page -- a Use-After-Free. Fix this by splitting the DMA release into two functions: 1. __page_pool_unmap_netmem_dma() caches dma_addr before xa_cmpxchg(), does the cmpxchg to remove the DMA mapping, and calls dma_unmap on the cached address. It never touches netmem fields after the cmpxchg, making it safe for the scrub path which holds no page ref. 2. __page_pool_release_netmem_dma() wraps the above and additionally clears dma_addr and DMA index bits in netmem fields. This is safe only when the caller holds a page ref, so it is used by the return path (page_pool_return_netmem). The scrub path calls __page_pool_unmap_netmem_dma() directly; the return path calls __page_pool_release_netmem_dma().
Title net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:18.838Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90201

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:15.053

Modified: 2026-09-17T17:17:15.053

Link: CVE-2026-90201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses