CVE-2026-97603 (GCVE-0-2026-97603)

Vulnerability from cvelistv5 – Published: 2026-09-25 10:22 – Updated: 2026-09-25 10:22
VLAI
Title
idpf: disable DIM work before freeing q_vectors
Summary
In the Linux kernel, the following vulnerability has been resolved: idpf: disable DIM work before freeing q_vectors idpf never drains the Tx/Rx DIM works before freeing the memory they live in. tx_dim and rx_dim are embedded in struct idpf_q_vector, they are queued from the NAPI poll via net_dim(), and idpf_vport_intr_rel() ends with kfree(rsrc->q_vectors). Nothing in the driver cancels them. idpf_tx_dim_work() and idpf_rx_dim_work() then run on freed memory: idpf_vport_intr_write_itr() writes the ITR register through q_vector->intr_reg.tx_itr / rx_itr, void __iomem pointers loaded out of the freed q_vector. No configuration is needed to get there -- IDPF_ITR_IS_DYNAMIC() is defined as (itr_mode) and idpf_vport_alloc() initialises both modes to IDPF_ITR_DYNAMIC. Draining after idpf_vport_intr_napi_dis_all() is not enough on its own. idpf_net_dim() is called from inside the "if (napi_complete_done(napi, work_done))" branch of the poll, and napi_complete_done() has already cleared NAPIF_STATE_SCHED by then. napi_disable_locked() waits only while (val & (NAPIF_STATE_SCHED | NAPIF_STATE_NPSVC)), so napi_disable() can return while the poll tail is still queueing the work, and a plain cancel_work_sync() would be re-armed behind the drain. Use disable_work_sync(): schedule_work() on a work with a non-zero disable count is dropped by clear_pending_if_disabled() before __queue_work() is reached. Move idpf_init_dim() to idpf_vport_intr_alloc() so the works are initialised on every path that can reach the drain -- the three "goto intr_deinit" sites between idpf_vport_intr_init() and idpf_vport_intr_ena() get there without the enable side having run. Nothing re-enables them: rsrc->q_vectors is freed on every exit from idpf_vport_open() and on every idpf_vport_stop(), so the count dies with the object. It is a race, not a deterministic failure -- net_dim() only schedules once DIM_NEVENTS events have accumulated and the profile index changes. A KASAN ifup/ifdown loop under load is the way to see it.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: c2d548cad1508d334517bcbd7cd5c915cc831fc0 , < 7e4312953788244d47074987d40d76702cf929f1 (git)
Affected: c2d548cad1508d334517bcbd7cd5c915cc831fc0 , < cd7a1598645b6917a8676b7e2efe8d97ce68a952 (git)
Affected: c2d548cad1508d334517bcbd7cd5c915cc831fc0 , < 7dd4c829bac2916be98a3e34b41daaba7f42b4c4 (git)
Create a notification for this product.
Linux Linux Affected: 6.7
Unaffected: 0 , < 6.7 (semver)
Unaffected: 6.18.53 , ≤ 6.18.* (semver)
Unaffected: 7.2.7 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc3 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/intel/idpf/idpf_txrx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "7e4312953788244d47074987d40d76702cf929f1",
              "status": "affected",
              "version": "c2d548cad1508d334517bcbd7cd5c915cc831fc0",
              "versionType": "git"
            },
            {
              "lessThan": "cd7a1598645b6917a8676b7e2efe8d97ce68a952",
              "status": "affected",
              "version": "c2d548cad1508d334517bcbd7cd5c915cc831fc0",
              "versionType": "git"
            },
            {
              "lessThan": "7dd4c829bac2916be98a3e34b41daaba7f42b4c4",
              "status": "affected",
              "version": "c2d548cad1508d334517bcbd7cd5c915cc831fc0",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/intel/idpf/idpf_txrx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "lessThan": "6.7",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.53",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.7",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc3",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: disable DIM work before freeing q_vectors\n\nidpf never drains the Tx/Rx DIM works before freeing the memory they\nlive in.  tx_dim and rx_dim are embedded in struct idpf_q_vector, they\nare queued from the NAPI poll via net_dim(), and idpf_vport_intr_rel()\nends with kfree(rsrc-\u003eq_vectors).  Nothing in the driver cancels them.\n\nidpf_tx_dim_work() and idpf_rx_dim_work() then run on freed memory:\nidpf_vport_intr_write_itr() writes the ITR register through\nq_vector-\u003eintr_reg.tx_itr / rx_itr, void __iomem pointers loaded out of\nthe freed q_vector.  No configuration is needed to get there --\nIDPF_ITR_IS_DYNAMIC() is defined as (itr_mode) and idpf_vport_alloc()\ninitialises both modes to IDPF_ITR_DYNAMIC.\n\nDraining after idpf_vport_intr_napi_dis_all() is not enough on its own.\nidpf_net_dim() is called from inside the\n\"if (napi_complete_done(napi, work_done))\" branch of the poll, and\nnapi_complete_done() has already cleared NAPIF_STATE_SCHED by then.\nnapi_disable_locked() waits only while (val \u0026 (NAPIF_STATE_SCHED |\nNAPIF_STATE_NPSVC)), so napi_disable() can return while the poll tail is\nstill queueing the work, and a plain cancel_work_sync() would be\nre-armed behind the drain.\n\nUse disable_work_sync(): schedule_work() on a work with a non-zero\ndisable count is dropped by clear_pending_if_disabled() before\n__queue_work() is reached.\n\nMove idpf_init_dim() to idpf_vport_intr_alloc() so the works are\ninitialised on every path that can reach the drain -- the three\n\"goto intr_deinit\" sites between idpf_vport_intr_init() and\nidpf_vport_intr_ena() get there without the enable side having run.\nNothing re-enables them: rsrc-\u003eq_vectors is freed on every exit from\nidpf_vport_open() and on every idpf_vport_stop(), so the count dies with\nthe object.\n\nIt is a race, not a deterministic failure -- net_dim() only schedules\nonce DIM_NEVENTS events have accumulated and the profile index changes.\nA KASAN ifup/ifdown loop under load is the way to see it."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T10:22:16.015Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7e4312953788244d47074987d40d76702cf929f1"
        },
        {
          "url": "https://git.kernel.org/stable/c/cd7a1598645b6917a8676b7e2efe8d97ce68a952"
        },
        {
          "url": "https://git.kernel.org/stable/c/7dd4c829bac2916be98a3e34b41daaba7f42b4c4"
        }
      ],
      "title": "idpf: disable DIM work before freeing q_vectors",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-97603",
    "datePublished": "2026-09-25T10:22:16.015Z",
    "dateReserved": "2026-09-24T16:01:01.158Z",
    "dateUpdated": "2026-09-25T10:22:16.015Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-97603",
      "date": "2026-10-02",
      "epss": "0.00198",
      "percentile": "0.0865"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/ethernet/intel/idpf/idpf_txrx.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "7e4312953788244d47074987d40d76702cf929f1",
                    "status": "affected",
                    "version": "c2d548cad1508d334517bcbd7cd5c915cc831fc0",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "cd7a1598645b6917a8676b7e2efe8d97ce68a952",
                    "status": "affected",
                    "version": "c2d548cad1508d334517bcbd7cd5c915cc831fc0",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "7dd4c829bac2916be98a3e34b41daaba7f42b4c4",
                    "status": "affected",
                    "version": "c2d548cad1508d334517bcbd7cd5c915cc831fc0",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/ethernet/intel/idpf/idpf_txrx.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "lessThan": "6.7",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.53",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.7",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc3",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: disable DIM work before freeing q_vectors\n\nidpf never drains the Tx/Rx DIM works before freeing the memory they\nlive in.  tx_dim and rx_dim are embedded in struct idpf_q_vector, they\nare queued from the NAPI poll via net_dim(), and idpf_vport_intr_rel()\nends with kfree(rsrc-\u003eq_vectors).  Nothing in the driver cancels them.\n\nidpf_tx_dim_work() and idpf_rx_dim_work() then run on freed memory:\nidpf_vport_intr_write_itr() writes the ITR register through\nq_vector-\u003eintr_reg.tx_itr / rx_itr, void __iomem pointers loaded out of\nthe freed q_vector.  No configuration is needed to get there --\nIDPF_ITR_IS_DYNAMIC() is defined as (itr_mode) and idpf_vport_alloc()\ninitialises both modes to IDPF_ITR_DYNAMIC.\n\nDraining after idpf_vport_intr_napi_dis_all() is not enough on its own.\nidpf_net_dim() is called from inside the\n\"if (napi_complete_done(napi, work_done))\" branch of the poll, and\nnapi_complete_done() has already cleared NAPIF_STATE_SCHED by then.\nnapi_disable_locked() waits only while (val \u0026 (NAPIF_STATE_SCHED |\nNAPIF_STATE_NPSVC)), so napi_disable() can return while the poll tail is\nstill queueing the work, and a plain cancel_work_sync() would be\nre-armed behind the drain.\n\nUse disable_work_sync(): schedule_work() on a work with a non-zero\ndisable count is dropped by clear_pending_if_disabled() before\n__queue_work() is reached.\n\nMove idpf_init_dim() to idpf_vport_intr_alloc() so the works are\ninitialised on every path that can reach the drain -- the three\n\"goto intr_deinit\" sites between idpf_vport_intr_init() and\nidpf_vport_intr_ena() get there without the enable side having run.\nNothing re-enables them: rsrc-\u003eq_vectors is freed on every exit from\nidpf_vport_open() and on every idpf_vport_stop(), so the count dies with\nthe object.\n\nIt is a race, not a deterministic failure -- net_dim() only schedules\nonce DIM_NEVENTS events have accumulated and the profile index changes.\nA KASAN ifup/ifdown loop under load is the way to see it."
          }
        ],
        "id": "CVE-2026-97603",
        "lastModified": "2026-09-25T11:17:13.393",
        "metrics": {},
        "published": "2026-09-25T11:17:13.393",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/7dd4c829bac2916be98a3e34b41daaba7f42b4c4"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/7e4312953788244d47074987d40d76702cf929f1"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/cd7a1598645b6917a8676b7e2efe8d97ce68a952"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "redhat_vex": {
      "aggregate_severity": "Moderate",
      "current_release_date": "2026-09-29T13:58:03+00:00",
      "cve": "CVE-2026-97603",
      "id": "CVE-2026-97603",
      "initial_release_date": "2026-09-25T00:00:00+00:00",
      "product_status:known_affected": "231",
      "product_status:known_not_affected": "45",
      "source": "Red Hat CSAF VEX",
      "status": "final",
      "title": "kernel: idpf: disable DIM work before freeing q_vectors",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-97603.json",
      "version": "3"
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-01T16:06:38Z",
      "cve": "CVE-2026-97603",
      "id": "CVE-2026-97603",
      "initial_release_date": "2026-10-01T16:06:38Z",
      "product_status:known_affected": "46",
      "product_status:known_not_affected": "301",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-97603",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-97603.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…