Description
In the Linux kernel, the following vulnerability has been resolved:

veth: manage XDP program pointers during channel resize

veth_set_channels() tears down XDP resources for removed RX queues
without clearing rq->xdp_prog. If the program is then detached or
replaced, those queues keep the old pointer after bpf_prog_put().
A later channel increase can re-enable NAPI and run the freed program.

BUG: unable to handle page fault for address: ffffc90000256048
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: veth_xdp_rcv_skb (include/linux/filter.h:779
include/net/xdp.h:696 drivers/net/veth.c:820)
Call Trace:
veth_xdp_rcv (drivers/net/veth.c:941)
veth_poll (drivers/net/veth.c:986)
__napi_poll (net/core/dev.c:7787)
net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007)
handle_softirqs (kernel/softirq.c:645)
Kernel panic - not syncing: Fatal exception in interrupt
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when the virtual Ethernet driver fails to clear XDP program pointers during channel resize. Removing a receive queue tears down XDP resources but leaves the pointer dangling; if the program is then detached or replaced, the freed pointer remains. When the channel size is increased again, NAPI is re‑enabled and the kernel executes the freed program, causing a kernel panic. This use‑after‑free can also allow an attacker to execute arbitrary code with kernel privileges, effectively elevating local privileges or causing a denial of service.

Affected Systems

The flaw exists in the Linux kernel’s veth driver and therefore impacts all Linux kernel releases that contain this code path until the patch is applied. No specific version range is given, so it should be treated as a potential risk to all current kernel releases until the upstream fix is merged and distributed.

Risk and Exploitability

The CVSS score is not supplied, but the bug involves a use‑after‑free in the kernel, which typically carries a high severity rating. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to manipulate veth channel counts or otherwise trigger a channel resize while XDP programs are attached. The likely attack vector is local, involving privileged or compromised users who can control network interfaces.

Generated by OpenCVE AI on October 9, 2026 at 09:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the veth XDP pointer cleanup fix (the upstream patch is in commit 1a5c5b9c).
  • If an immediate kernel upgrade is not possible, detach any XDP programs from affected veth interfaces before resizing the channel or avoid resizing entirely until the patch is applied.
  • Verify that XDP program pointers are cleared by running `ip link set dev <veth> xdp off` before modifying the interface.
  • Monitor kernel logs for Oops or panic messages as indicators of exploitation attempts.

Generated by OpenCVE AI on October 9, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: veth: manage XDP program pointers during channel resize veth_set_channels() tears down XDP resources for removed RX queues without clearing rq->xdp_prog. If the program is then detached or replaced, those queues keep the old pointer after bpf_prog_put(). A later channel increase can re-enable NAPI and run the freed program. BUG: unable to handle page fault for address: ffffc90000256048 Oops: Oops: 0000 [#1] SMP KASAN NOPTI RIP: veth_xdp_rcv_skb (include/linux/filter.h:779 include/net/xdp.h:696 drivers/net/veth.c:820) Call Trace: veth_xdp_rcv (drivers/net/veth.c:941) veth_poll (drivers/net/veth.c:986) __napi_poll (net/core/dev.c:7787) net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007) handle_softirqs (kernel/softirq.c:645) Kernel panic - not syncing: Fatal exception in interrupt
Title veth: manage XDP program pointers during channel resize
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:21.029Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98381

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.547

Modified: 2026-10-09T08:16:56.547

Link: CVE-2026-98381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses