Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: net: Stop leased rxq before uninstalling its memory provider… (CVE-2026-74285)
In the Linux kernel, the following vulnerability has been resolved: net: Stop leased rxq before uninstalling its memory provider netif_rxq_cleanup_unlease() tears down the memory provider that was installed on a physical RX queue through a netkit queue lease. It currently revokes the provider's DMA mappings before stopping the physical queue: __netif_mp_uninstall_rxq(virt_rxq, p); /* DMA unmap */ __netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p); /* queue stop */ This inverts the ordering used by the regular teardown paths (normal device unregister and the io_uring zcrx close path), which stop the queue before revoking the provider's mappings. With the physical queue still live, its NAPI can keep consuming net_iov entries from the page_pool alloc cache after the __netif_mp_uninstall_rxq() has already cleared their dma_addr, opening a window for the device to DMA to a stale or zero address. Fix it by swapping the two calls so the queue is stopped (and its NAPI quiesced) before the provider is uninstalled. No functional regression was observed across repeated runs of the nk_qlease.py HW selftest, which exercises the lease teardown path; this was tested against fbnic QEMU emulation.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-74285) in the Linux kernel relates to the netif_rxq_cleanup_unlease() function, which improperly orders the teardown steps of a leased RX queue's memory provider. Specifically, it revoked DMA mappings before stopping the physical RX queue, leaving the queue active and allowing its NAPI to consume net_iov entries referencing cleared DMA addresses. This could open a window for the device to perform DMA to invalid memory addresses. The fix swaps the order of operations to stop the queue first, quiescing NAPI before uninstalling the memory provider, eliminating the race condition. Testing showed no functional regressions.
Potential Impact
The vulnerability could allow a device to perform DMA operations to stale or zeroed memory addresses, potentially leading to memory corruption or undefined behavior in the kernel's network stack. No known exploits in the wild have been reported. The impact is limited to the affected kernel network code handling leased RX queues and DMA mappings.
Mitigation Recommendations
A fix has been implemented that changes the order of operations to stop the RX queue before uninstalling its memory provider, preventing the race condition. Since no explicit patch links or vendor advisories are provided, check the official Linux kernel repositories or vendor advisories for the patch corresponding to CVE-2026-74285 and update affected kernel versions accordingly.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: net: Stop leased rxq before uninstalling its memory provider… (CVE-2026-74285)
Description
In the Linux kernel, the following vulnerability has been resolved: net: Stop leased rxq before uninstalling its memory provider netif_rxq_cleanup_unlease() tears down the memory provider that was installed on a physical RX queue through a netkit queue lease. It currently revokes the provider's DMA mappings before stopping the physical queue: __netif_mp_uninstall_rxq(virt_rxq, p); /* DMA unmap */ __netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p); /* queue stop */ This inverts the ordering used by the regular teardown paths (normal device unregister and the io_uring zcrx close path), which stop the queue before revoking the provider's mappings. With the physical queue still live, its NAPI can keep consuming net_iov entries from the page_pool alloc cache after the __netif_mp_uninstall_rxq() has already cleared their dma_addr, opening a window for the device to DMA to a stale or zero address. Fix it by swapping the two calls so the queue is stopped (and its NAPI quiesced) before the provider is uninstalled. No functional regression was observed across repeated runs of the nk_qlease.py HW selftest, which exercises the lease teardown path; this was tested against fbnic QEMU emulation.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-74285) in the Linux kernel relates to the netif_rxq_cleanup_unlease() function, which improperly orders the teardown steps of a leased RX queue's memory provider. Specifically, it revoked DMA mappings before stopping the physical RX queue, leaving the queue active and allowing its NAPI to consume net_iov entries referencing cleared DMA addresses. This could open a window for the device to perform DMA to invalid memory addresses. The fix swaps the order of operations to stop the queue first, quiescing NAPI before uninstalling the memory provider, eliminating the race condition. Testing showed no functional regressions.
Potential Impact
The vulnerability could allow a device to perform DMA operations to stale or zeroed memory addresses, potentially leading to memory corruption or undefined behavior in the kernel's network stack. No known exploits in the wild have been reported. The impact is limited to the affected kernel network code handling leased RX queues and DMA mappings.
Mitigation Recommendations
A fix has been implemented that changes the order of operations to stop the RX queue before uninstalling its memory provider, preventing the race condition. Since no explicit patch links or vendor advisories are provided, check the official Linux kernel repositories or vendor advisories for the patch corresponding to CVE-2026-74285 and update affected kernel versions accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v8cx-r8w6-r2xr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74285"]
Threat ID: 6a808b6bbf8831d5394f788d
Added to database: 08/15/2026, 15:53:15 UTC
Last enriched: 08/15/2026, 16:12:55 UTC
Last updated: 09/30/2026, 06:54:41 UTC
Views: 44
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.