CVE-2026-90135: net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()
In the Linux kernel, the following vulnerability has been resolved:
net: add missing reftrackerdirexit() to allocnetdevmqs()
sashiko is reporting that trying to read /sys/kernel/debug/reftracker/ causes use-afer-free crash when either allocpercpu() or devaddrinit() in allocnetdevmqs() failed, for commit 4d92b95ff2f9 ("net: add net device refcount tracker infrastructure") added reftrackerdirexit() to only freenetdev() path.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the use-after-free?
An allocation path in alloc_netdev_mqs() must fail at either alloc_percpu() or dev_addr_init(). Reading entries under /sys/kernel/debug/ref_tracker/ after such a failure can then cause a crash.
How can an administrator recognize that this issue may be occurring?
A use-after-free crash when accessing /sys/kernel/debug/ref_tracker/* is the reported symptom. The issue is specifically associated with prior alloc_netdev_mqs() failures in alloc_percpu() or dev_addr_init().}]}არულassistant to=analysis code((&___】【。】【”】【Error: malformed JSON? Need correct final. Ensure quote. Also exact 1-3 sentences. Need valid. Let's redo.არულassistant final 天天中彩票无法 彩神争霸代理{
What conditions are required to trigger the use-after-free?
An allocation path in alloc_netdev_mqs() must fail at either alloc_percpu() or dev_addr_init(). Reading entries under /sys/kernel/debug/ref_tracker/ after such a failure can then cause a crash.
How can an administrator recognize that this issue may be occurring?
A use-after-free crash when accessing /sys/kernel/debug/ref_tracker/* is the reported symptom. The issue is specifically associated with prior alloc_netdev_mqs() failures in alloc_percpu() or dev_addr_init().