CVE-2026-53298
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
net: airoha: Verplaats ndesc initialisatie aan het einde van airoha_qdma_init_rx_queue()
Als de toewijzing van de wachtrijinvoer of de DMA-descriptorlijst mislukt in
airoha_qdma_init_rx_queue routine, airoha_qdma_cleanup() zal een
NULL pointer dereferentie actief netif_napi_del() voor RX-wachtrij NAPI's
aangezien netif_napi_add() nooit is uitgevoerd voor deze specifieke RX NAPI. Het probleem is te wijten aan de vroege ndesc-initialisatie in
airoha_qdma_init_rx_queue() aangezien airoha_qdma_cleanup() afhankelijk is van ndesc
waarde om te controleren of de wachtrij correct is geïnitialiseerd. Los het probleem op bij het verplaatsen
ndesc initialisatie aan het einde van airoha_qdma_init_tx routine. Verplaats page_pool toewijzing na descriptor lijst toewijzing om
vermijd geheugenlekken als DESC-toewijzing mislukt.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue()
If queue entry or DMA descriptor list allocation fails in
airoha_qdma_init_rx_queue routine, airoha_qdma_cleanup() will trigger a
NULL pointer dereference running netif_napi_del() for RX queue NAPIs
since netif_napi_add() has never been executed to this particular RX NAPI.
The issue is due to the early ndesc initialization in
airoha_qdma_init_rx_queue() since airoha_qdma_cleanup() relies on ndesc
value to check if the queue is properly initialized. Fix the issue moving
ndesc initialization at end of airoha_qdma_init_tx routine.
Move page_pool allocation after descriptor list allocation in order to
avoid memory leaks if desc allocation fails.