CVE-2026-72493: net: serialize netif_running() check in enqueue_to_backlog()
In the Linux kernel, the following vulnerability has been resolved:
net: serialize netifrunning() check in enqueuetobacklog()
Syzbot reported a KASAN slab-use-after-free in fibruleslookup().
The root cause is a race condition where packets can escape the backlog flushing during device unregistration (e.g., during netns exit).
Commit e9e4dd3267d0 ("net: do not process device backlog during unregistration") introduced a lockless netifrunning() check in enqueuetobacklog() to prevent queuing packets to an unregistering device.
However, this creates a TOCTOU race window.
A lockless transmitter (like vethxmit) can pass the check before devclose() clears IFFUP. If the transmitter is then delayed, flushallbacklogs() can run and finish before the transmitter grabs the backlog lock and queues the packet. The packet then escapes the flush and triggers UAF later when processed.
Fix this by moving the netifrunning() check inside the backlog lock. This serializes the check with the flush work (which also grabs the lock). We then either queue the packet before the flush runs (so it gets flushed), or check netifrunning() after the flush/close completes (so it gets dropped).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72493?
The severity of CVE-2026-72493 is rated at 55.
What does CVE-2026-72493 involve?
CVE-2026-72493 involves a race condition in the Linux kernel leading to KASAN slab-use-after-free vulnerabilities.
How do I fix CVE-2026-72493?
To fix CVE-2026-72493, ensure that you update your Linux kernel to the patched version released after August 15, 2026.
What are the potential impacts of CVE-2026-72493?
The potential impacts of CVE-2026-72493 include packet loss due to race conditions in the network processing mechanism.
Who reported the issue related to CVE-2026-72493?
The issue related to CVE-2026-72493 was reported by Syzbot.