PT-2026-64756 · Linux · Linux
CVE-2026-64525
·
Publicado
2026-07-25
·
Atualizado
2026-07-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
xfrm: move policy bydst RCU sync from per-netns .exit to .pre exit
The struct pernet operations docstring in include/net/net namespace.h
explicitly warns against blocking RCU primitives in .exit handlers:
Exit methods using blocking RCU primitives, such as
synchronize rcu(), should be implemented via exit batch.
[...]
Please, avoid synchronize rcu() at all, where it's possible.
Note that a combination of pre exit() and exit() can
be used, since a synchronize rcu() is guaranteed between
the calls.
xfrm policy fini() violates this: it calls synchronize rcu() before
freeing the policy bydst hash tables (so no RCU reader is mid-
traversal at free time), but runs from xfrm net ops.exit -- once per
namespace -- so a cleanup net() of N namespaces pays N full RCU
grace periods serially.
Use the documented pre exit/exit split. Move the policy flush (and
the workqueue drains it depends on) into a new .pre exit handler;
xfrm policy fini() then runs in .exit and frees the hash tables
after the synchronize rcu expedited() that cleanup net() guarantees
between the two phases. Providing O(1) RCU grace periods per batch
instead of O(N).
Observed on Linux 6.18 with a workload doing unshare(CLONE NEWNET)
at ~13/sec sustained: cleanup net() and the netns wq rescuer kthread
both stuck in xfrm policy fini()'s synchronize rcu(), >300k struct
net accumulated in the cleanup queue, Percpu in /proc/meminfo climbed
to 130+ GB on 256-CPU hosts, and memcg OOMs followed. setup net and
put net counts were balanced, ruling out a refcount leak.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux