From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 04ED757F752 for ; Fri, 11 Sep 2026 19:50:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156234; cv=none; b=NN9D9XzHq0nuI2MWnO/FqRCUo178eNJyg17YnzPSjmPo7eizU0swC7da/3dVnHktSa868pFnuC0GhQ3w51+RdwXE2FQloml2RAcwonXilI+D/14vcqk4yf6Q8+GloaZ0waG/jUN8a4pqksXCDlqR8BBS7SJ4Bcgmf/7rfSbpwZs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156234; c=relaxed/simple; bh=hlYFKwHDLhuuLprf3EpyUU/uDXYOfN8pSZlPQi0da4E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qeAgA2xRKBKdXp6ZgteRsFZIxS99HQLzgIzrg8zJADXCPhbwJd/ML0DnjPe8NaarXJ/KH6J6EYJTSvCLv7gXrfyRaoQ3vNso/rN+L5h8wVRtIal996bD9NtuR8FVAlI1Pacodoajz4KDl4LnxJRz/inb+9lQ1peqcb3yre6PUTI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=hMD8sueE; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="hMD8sueE" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 03AB81F00893; Fri, 11 Sep 2026 19:50:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156221; bh=2vS0wnu4fZ+rlpbdLVOE1SFPewADFkK3ZKpnuYYjRXI=; h=From:To:Cc:Subject:Date:Reply-To; b=hMD8sueEitb29/TErQz1+0Er7G5AB1UfHSkkPCj+XK1VqySD3X6Xehwy1s780Agw9 V5w0QjEGP2GGSL3EE+DDxnA6ubOML/liQzSV9S18U9AYKfRYDNBvtribnhk1C/RUuG erPSxJ4A8U+cWu80omy911nzYXFbxkkN2UqKTaUU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80994: net: openvswitch: fix flow mask use-after-free on flow deletion Date: Fri, 11 Sep 2026 21:41:40 +0200 Message-ID: <2026091149-CVE-2026-80994-d032@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4858; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=L4l5cD4n/d8RNbKhkg5smwcxeGaIas8Boz/VeCDKu2M=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIh09quum7so72uD9IHTiDOmvMrevL7wg9D/Betvz0 ka+m/GhHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRdb8Z5tke+jtplaD4PtaT rCmrpjwRTZy0aynD/OB9uXcFpE3DlWf++vA0fPtToTvMHQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on flow deletion The commit in the Fixes tag below made so flow->mask free is scheduled via RCU right after it is removed from the flow table. The pointer stays in the flow structure and it can be accessible while in the same RCU critical section. This is done to avoid requiring ovs_mutex for the ovs_flow_free(). However, while removing the flow during processing of CMD_DEL, we do not take RCU read lock before the removal, and ovs_flow_cmd_fill_info() uses the flow->mask pointer afterwards. The RCU read lock is taken, but it's already late at that point. The comment on that line acknowledges that the lock is cosmetic and doesn't serve a real purpose. This leads to use-after-free if the RCU grace period passes between removal and the filling. It is a short race window, but it is there and can lead to a real crash in case memory allocation for the info takes a bit longer: BUG: KASAN: slab-use-after-free in __ovs_nla_put_key net/openvswitch/flow_netlink.c:1996 BUG: KASAN: slab-use-after-free in ovs_nla_put_key+0x2463/0x2e30 net/openvswitch/flow_netlink.c:2250 Read of size 4 at addr ffff88801ee89970 by task ovs_flow_del_ec/9487 Call Trace: __ovs_nla_put_key net/openvswitch/flow_netlink.c:1996 ovs_nla_put_key+0x2463/0x2e30 net/openvswitch/flow_netlink.c:2250 ovs_flow_cmd_fill_info+0x420/0x9c0 net/openvswitch/datapath.c:930 ovs_flow_cmd_del+0x53a/0x970 net/openvswitch/datapath.c:1467 ... netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556 Allocated by task 9487: mask_alloc net/openvswitch/flow_table.c:967 flow_mask_insert net/openvswitch/flow_table.c:1012 ovs_flow_tbl_insert+0xea2/0x1a90 net/openvswitch/flow_table.c:1084 ovs_flow_cmd_new+0x7e3/0xd90 net/openvswitch/datapath.c:1086 ... netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556 Freed by task 9485: rcu_free_sheaf+0x1e/0x100 mm/slub.c:5978 rcu_do_batch kernel/rcu/tree.c:2645 rcu_core+0x59c/0x10c0 kernel/rcu/tree.c:2897 handle_softirqs+0x1e4/0x9a0 kernel/softirq.c:622 ... instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 ovs_flow_tbl_remove() must be called after the ovs_flow_cmd_fill_info() to avoid this race. This also helps with cleaning up the forced cast and the cosmetic RCU read lock. Before the commit in the Fixes tag the order did not matter as long as the flow object itself was not freed. A wider RCU critical section could be another option, but we have a GFP_KERNEL allocation in the way. Reported by Trend Micro's Zero Day Initiative as ZDI-CAN-32042. The Linux kernel CVE team has assigned CVE-2026-80994 to this issue. Affected and fixed versions =========================== Issue introduced in 3.16 with commit 56c19868e115fcf8d62d843e1b9616bb9837d0db and fixed in 6.12.109 with commit 0ba5cbc2f049af94ec94ff6f64958545efc5eaa2 Issue introduced in 3.16 with commit 56c19868e115fcf8d62d843e1b9616bb9837d0db and fixed in 6.18.50 with commit ac73e3af571da06c1d1cfe3f0f00dc978b851700 Issue introduced in 3.16 with commit 56c19868e115fcf8d62d843e1b9616bb9837d0db and fixed in 7.2.4 with commit 7f072b84afd05a77963eb1872f7174e280661dce Issue introduced in 3.16 with commit 56c19868e115fcf8d62d843e1b9616bb9837d0db and fixed in 7.3-rc1 with commit 4e30317ff67a2eb12b4d890d39f72fd7e7117d48 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80994 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/openvswitch/datapath.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0ba5cbc2f049af94ec94ff6f64958545efc5eaa2 https://git.kernel.org/stable/c/ac73e3af571da06c1d1cfe3f0f00dc978b851700 https://git.kernel.org/stable/c/7f072b84afd05a77963eb1872f7174e280661dce https://git.kernel.org/stable/c/4e30317ff67a2eb12b4d890d39f72fd7e7117d48