CVE-2026-31646
In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() page_pool_create() can return an ERR_PTR on failure. The return value is used unconditionally in the loop that follows, passing the error pointer through xdp_rxq_info_reg_mem_model() into page_pool_use_xdp_mem(), which dereferences it, causing a kernel oops. Add an IS_ERR check after page_pool_create() to return early on failure.
वीकनेस
In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() page_pool_create() can return an ERR_PTR on failure. The return value is used unconditionally in the loop that follows, passing the error pointer through xdp_rxq_info_reg_mem_model() into page_pool_use_xdp_mem(), which dereferences it, causing a kernel oops. Add an IS_ERR check after page_pool_create() to return early on failure.
प्रभावित प्रोडक्ट
- linux linux_kernel
संदर्भ
- https://git.kernel.org/stable/c/305832c53551cfbe6e5b81ca7ee765e60f4fe8e9
- https://git.kernel.org/stable/c/3fd0da4fd8851a7e62d009b7db6c4a05b092bc19
- https://git.kernel.org/stable/c/7caf90d9ab97951a58d1de85ab7e7d7cca7a4513
- https://git.kernel.org/stable/c/b5dcb41ba891b55157006cac79825c78a32b409e
- https://git.kernel.org/stable/c/e63265f188ea39dcf5f546770650027528f3bd0f
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।