CVE-2026-23454

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Queue (EQ) are destroyed. This allows an in-flight CQ interrupt handler to dereference freed memory, leading to a use-after-free or NULL pointer dereference in mana_hwc_handle_resp(). mana_smc_teardown_hwc() signals the hardware to stop but does not synchronize against IRQ handlers already executing on other CPUs. The IRQ synchronization only happens in mana_hwc_destroy_cq() via mana_gd_destroy_eq() -> mana_gd_deregister_irq(). Since this runs after kfree(hwc->caller_ctx), a concurrent mana_hwc_rx_event_handler() can dereference freed caller_ctx (and rxq->msg_buf) in mana_hwc_handle_resp(). Fix this by reordering teardown to reverse-of-creation order: destroy the TX/RX work queues and CQ/EQ before freeing hwc->caller_ctx. This ensures all in-flight interrupt handlers complete before the memory they access is freed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: mana: corrige uso después de liberación en mana_hwc_destroy_channel() reordenando el desmantelamiento Existe una potencial condición de carrera en mana_hwc_destroy_channel() donde hwc -> caller_ctx es liberado antes de que la Cola de Completado (CQ) y la Cola de Eventos (EQ) del HWC sean destruidas. Esto permite a un gestor de interrupciones de CQ en curso desreferenciar memoria liberada, lo que lleva a un uso después de liberación o a una desreferencia de puntero NULL en mana_hwc_handle_resp(). mana_smc_teardown_hwc() le indica al hardware que se detenga pero no se sincroniza con los gestores de IRQ que ya se están ejecutando en otras CPUs. La sincronización de IRQ solo ocurre en mana_hwc_destroy_cq() a través de mana_gd_destroy_eq() -> mana_gd_deregister_irq(). Dado que esto se ejecuta después de kfree(hwc -> caller_ctx), un mana_hwc_rx_event_handler() concurrente puede desreferenciar caller_ctx liberado (y rxq -> msg_buf) en mana_hwc_handle_resp(). Solucione esto reordenando el desmantelamiento al orden inverso de creación: destruya las colas de trabajo TX/RX y CQ/EQ antes de liberar hwc -> caller_ctx. Esto asegura que todos los gestores de interrupciones en curso se completen antes de que la memoria a la que acceden sea liberada.

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

26 May 2026, 14:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/05d345719d85b927cba74afac4d5322de3aa4256 - () https://git.kernel.org/stable/c/05d345719d85b927cba74afac4d5322de3aa4256 - Patch
References () https://git.kernel.org/stable/c/249e905571583a434d4ea8d6f92ccc0eef337115 - () https://git.kernel.org/stable/c/249e905571583a434d4ea8d6f92ccc0eef337115 - Patch
References () https://git.kernel.org/stable/c/2b001901f689021acd7bf2dceed74a1bdcaaa1f9 - () https://git.kernel.org/stable/c/2b001901f689021acd7bf2dceed74a1bdcaaa1f9 - Patch
References () https://git.kernel.org/stable/c/afdb1533eb9c05432aeb793a7280fa827c502f5c - () https://git.kernel.org/stable/c/afdb1533eb9c05432aeb793a7280fa827c502f5c - Patch
References () https://git.kernel.org/stable/c/b88edf12fc3779521ae5f6f1584153b15f7da6df - () https://git.kernel.org/stable/c/b88edf12fc3779521ae5f6f1584153b15f7da6df - Patch
References () https://git.kernel.org/stable/c/e23bf444512cb85d76012080a76cd1f9e967448e - () https://git.kernel.org/stable/c/e23bf444512cb85d76012080a76cd1f9e967448e - Patch
References () https://git.kernel.org/stable/c/fa103fc8f56954a60699a29215cb713448a39e87 - () https://git.kernel.org/stable/c/fa103fc8f56954a60699a29215cb713448a39e87 - Patch
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
CWE CWE-416

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/b88edf12fc3779521ae5f6f1584153b15f7da6df -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-23454

Mitre link : CVE-2026-23454

CVE.ORG link : CVE-2026-23454


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free