Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97955— net: mana: restore the XDP program pointer when pre-allocation fails

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: net: mana: 预分配失败时恢复 XDP 程序指针 函数在分配任何资源之前,就会将新的 XDP 程序发布到 中,因为 需要通过 从该程序获取配置信息来设置缓冲区大小。当预分配失败时,函数直接返回错误,跳过了 标签,而该标签是唯一一处恢复之前程序指针的地方。 此时, attach 操作被报告为失败,因此 BPF 核心会释放调用者所持有的引用,允许该程序被释放,但 仍然指向已被释放的内存。随后, 的下一个使用者——通常是在下一次 时由 中的 调用,或在 TX 超时重置

AI Predicted 7.8 Difficulty: Easy EPSS 0.17% · P5

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux 730ff06d3f5cc2ce0348414b78c10528b767d4a3< 5b3cdc9abd82b7e49e0f1a21d6eb75466c5ecef8 affected
730ff06d3f5cc2ce0348414b78c10528b767d4a3< 9801edfba8dfcdb1da3b0afccdf143e13d646b56 affected
730ff06d3f5cc2ce0348414b78c10528b767d4a3< 4c46beb807efcc93f5899ebe1f5958248eb296c6 affected
6.18 affected
< 6.18 unaffected
6.18.53≤ 6.18.* unaffected
7.2.7≤ 7.2.* unaffected
7.3-rc3≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97955

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: mana: restore the XDP program pointer when pre-allocation fails
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: mana: restore the XDP program pointer when pre-allocation fails mana_xdp_set() publishes the new program into apc->bpf_prog before it allocates anything, because mana_pre_alloc_rxbufs() sizes the buffers from it via mana_get_rxbuf_cfg(). When that allocation fails the function returns the error directly, skipping the err_dealloc_rxbuffs label which is the only place that restores the previous pointer. The attach is reported as failed, so the BPF core drops the reference it held for the caller and the program can be freed, while apc->bpf_prog still points at it. The next consumer of mana_xdp_get() - typically mana_chn_setxdp() from mana_alloc_queues() on the following ifup, or after a TX timeout reset - then calls bpf_prog_add() on freed memory. This is reachable from an ordinary "ip link set dev ethX xdp obj ..." whenever the per-queue RX buffer pre-allocation cannot be satisfied. Restore the previous program on that error path.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 730ff06d3f5cc2ce0348414b78c10528b767d4a3 ~ 5b3cdc9abd82b7e49e0f1a21d6eb75466c5ecef8 -
Linux Linux 6.18 -

II. Public POCs for CVE-2026-97955

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97955

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97955 (3)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-97937 7.8 HIGH ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97955

No comments yet


Leave a comment