CVE-2026-98286: drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

dropmonitor: use timershutdownsync() to prevent timer rearming during teardown

In dropmonitor teardown paths (netdmtraceoffset(), netdmhwmonitorstop(), and error unwind paths in netdmtraceonset() and netdmhwmonitorstart()), per-CPU timers are stopped using timerdeletesync() followed by cancelworksync().

However, there is a circular dependency between sendtimer and dmalertwork: 1) schedsendwork() (timer callback) schedules dmalertwork. 2) senddmalert() / netdmhwsummarywork() calls resetpercpudata() or netdmhwresetpercpudata(). 3) If memory allocation fails under memory pressure in the reset function, it re-arms the timer via modtimer(&data->sendtimer, ...).

If dmalertwork is running concurrently while timerdeletesync() executes on another CPU, an allocation failure in the worker will re-arm the timer after timerdeletesync() has already returned. Once cancelworksync() completes and moduleput() is called, the timer remains active in the timer wheel. If the module is then unloaded, the timer will fire and execute schedsendwork() in freed memory, triggering a kernel panic / use-after-free.

Switch from timerdeletesync() to timershutdownsync(). This guarantees that any in-flight timer handler has finished and prevents subsequent re-arming attempts from running workers from succeeding. When monitoring is restarted later, timersetup() is invoked, which cleanly re-initializes the timer.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Replace timer_delete_sync() with timer_shutdown_sync() in drop_monitor teardown paths, including net_dm_trace_off_set(), net_dm_hw_monitor_stop(), net_dm_trace_on_set() error unwind paths, and net_dm_hw_reset_per_cpu_data(), to prevent timer rearming during teardown.

    Linux kernel drop_monitor timer teardown function = timer_shutdown_sync()

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203