Database/Kernel, userspace & hypervisor
Linux kernel BPF conntrack kfuncs: racing opts update unbalances the netns reference count
Impact
__bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read opts->netns_id separately when taking and releasing the namespace reference, and opts can point into a shared map value that another CPU is writing. A concurrent flip either leaks a reference or performs a put_net() with no matching get; repeating the unmatched put destroys a live network namespace and crashes a later user. The kernel report shows a general protection fault with a KASAN null-pointer-deref during a BPF program test run. This lives in the conntrack kfuncs that CNI and network-policy datapaths use, so a fault takes down the node's networking and the node with it.
Who can reach it
Requires a loaded BPF program calling the conntrack kfuncs with opts in a shared map value - CAP_BPF/CAP_NET_ADMIN, i.e. the cluster network datapath or a privileged agent, not a tenant pod. Triggering the imbalance needs concurrent writes to that map value while the kfunc runs.
What to do
Update to a stable kernel carrying the READ_ONCE() snapshot fix and reboot. No user-space knob mitigates this short of not running BPF programs that pass a shared map value as opts, which is a change to the CNI datapath rather than an operator setting. Fold it into the next kernel roll.
References
Related entries
- Linux kernel SMC-R: duplicate LLC link messages from a peer leak one kmalloc-96 object eachCVE-2026-74719 · Linux kernel SMC-R LLC event handler (duplicate CONFIRM_LINK / ADD_LINK_CONT qentry)Unscored
- Linux kernel BPF verifier: commuted pointer arithmetic loses pointer provenance stateCVE-2026-74720 · Linux kernel BPF verifier (adjust_ptr_min_max_vals, scalar += pointer)Unscored
- Linux kernel sched_ext: a failed sub-scheduler enable races root disable into a use-after-freeCVE-2026-74731 · Linux kernel sched_ext (scx_sub_disable teardown of never-linked sub-schedulers)Unscored
- Linux kernel perf/core: exited event accepted as group leader leaves a sibling pointing at freed memoryCVE-2026-74753 · Linux kernel perf/core (perf_event_open group-leader state validation)Unscored
- Xen: guest with a passthrough PCI device exposing an IO port BAR can trigger a hypervisor BUG()CVE-2026-79602 · Xen hypervisor (PCI passthrough, IO port BAR handling)Unscored
- libcurl: pooled TLS connection outlives its easy handle and reuses a freed OpenSSL library contextCVE-2026-80229 · libcurl (multi interface, OpenSSL 3 provider library context)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.