From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D3BC4FC8E4 for ; Fri, 4 Sep 2026 16:48:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540523; cv=none; b=Iulw99L93/tY/L0qLFtsmAjIBDGM2b7BPl5Wil3lVAZRaUpgV/LY6y61jtzhwotFPe4Oe0+Rlph7nAtT/IB1Qmt4brtykawZ/k9j+4o+2JFGiScS0kjX/dSKXP6mzgLvhYemlywBjs+hPWrua1esXPVhZ0iTRjXpLvtDgy4yjB4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540523; c=relaxed/simple; bh=sBYq63lhaSYLcjJk/OcRR12PhQ6LMZ2jgXhWkAHybY0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Q/jZECdF7LTCQD4rMEw9E2NHC8mDNYz7Ql/6Qj2pl9/H1v47oDkuAinnJnOPjFjBbfwlIVN/HdfdavUT8I98E7+3ZFMALtGu3P5lnJgCsgGPvq+mZK8DVLuxKIZSOV/5aB+FOTguhgN5BsaVGhEgrUAfIL0hSF7iK+0gyJ6XLfE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=f2agGMfH; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="f2agGMfH" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 43AD31F00AC4; Fri, 4 Sep 2026 16:48:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788540520; bh=lRzSPGFOsnz5rNXuWRQLz+T0PalmtItHZavVeyeKEv0=; h=From:To:Cc:Subject:Date:Reply-To; b=f2agGMfHLHxqUtXA0ZDbEXUfXjBHOxJ9ieAo+DtNBJHO3Di9yhkMg/HEzyH/0ftch IW/M8o51Ala10NgKAvXPd+pqrPGIUk9F/GwgFLEb2pdbW+FB3tgBxRdCdqoMHDZHLD CXNrlpe4XKw4b5xUq3fvYdjx8V9Dmq02B4Z8jOqw= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80866: tipc: avoid busy looping in tipc_exit_net() Date: Fri, 4 Sep 2026 18:46:33 +0200 Message-ID: <2026090433-CVE-2026-80866-8012@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2995; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=L6Fwgqui/Jxp/1dvAakB7AgljAi8osKKZ6vvE7OFAZc=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzvr58OrvjpklRzWGpq+tbJc6Ir7u2463L2Yxda981f mf3uyNv0BHLwiDIxCArpsjyZRvP0f0VhxS9DG1Pw8xhZQIZwsDFKQATWfWRYcGCAyxRcurX6rRc 0iVY/O+dVBPZNIdhfn2or0e5NvflrP7yjPaAk8X/yldPAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: tipc: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete: while (atomic_read(&tn->wq_count)) cond_resched(); This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups. Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero. Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero. This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed. The Linux kernel CVE team has assigned CVE-2026-80866 to this issue. Affected and fixed versions =========================== Issue introduced in 5.13 with commit 04c26faa51d1e2fe71cf13c45791f5174c37f986 and fixed in 7.1.5 with commit 522d1d950b9e3b68190a6de7534827c8dccedb73 Issue introduced in 5.13 with commit 04c26faa51d1e2fe71cf13c45791f5174c37f986 and fixed in 7.2 with commit c1481c94e74c955e0448ddf46b8615a44d840c1e Issue introduced in 5.4.124 with commit d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa Issue introduced in 5.10.42 with commit 5195ec5e365a2a9331bfeb585b613a6e94f98dba Issue introduced in 5.12.9 with commit b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80866 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/tipc/core.c net/tipc/udp_media.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/522d1d950b9e3b68190a6de7534827c8dccedb73 https://git.kernel.org/stable/c/c1481c94e74c955e0448ddf46b8615a44d840c1e