CVE-2026-53096 Details
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path The DEVMAP_HASH branch in dev_map_redirect_multi() uses hlist_for_each_entry_safe() to iterate hash buckets, but this function runs under RCU protection (called from xdp_do_generic_redirect_map() in softirq context). Concurrent writers (__dev_map_hash_update_elem, dev_map_hash_delete_elem) modify the list using RCU primitives (hlist_add_head_rcu, hlist_del_rcu). hlist_for_each_entry_safe() performs plain pointer dereferences without rcu_dereference(), missing the acquire barrier needed to pair with writers' rcu_assign_pointer(). On weakly-ordered architectures (ARM64, POWER), a reader can observe a partially-constructed node. It also defeats CONFIG_PROVE_RCU lockdep validation and KCSAN data-race detection. Replace with hlist_for_each_entry_rcu() using rcu_read_lock_bh_held() as the lockdep condition, consistent with the rcu_dereference_check() used in the DEVMAP (non-hash) branch of the same functions. Also fix the same incorrect lockdep_is_held(&dtab->index_lock) condition in dev_map_enqueue_multi(), where the lock is not held either.
A vulnerability in the Linux kernel's handling of the DEVMAP_HASH branch within the 'dev_map_redirect_multi()' function has been addressed. This vulnerability arose because the iteration over hash buckets used 'hlist_for_each_entry_safe()', which is not compatible with the RCU (Read-Copy-Update) protection required in this context. Concurrent writers modifying the list with RCU primitives could lead to a reader observing a partially-constructed node, particularly on weakly-ordered architectures like ARM64 and POWER'. This issue also interfered with RCU lock dependency validation and data race detection. The vulnerability has been fixed by replacing the unsafe iteration with 'hlist_for_each_entry_rcu()', ensuring proper RCU handling and restoring the integrity of the iteration process.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/4a3d0fe30b907ff324b1b49756f7e713d67f3645 | kernel.org | Patch |
| https://git.kernel.org/stable/c/571a05ea1baaccc0dc1e0d227b2cbc978b96d392 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7027e705062482a8cea43a1c13ede3c35653966f | kernel.org | Patch |
| https://git.kernel.org/stable/c/8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b089aa6e94d7a08e74d076a0fe274842dc9feccc | kernel.org | Patch |
| https://git.kernel.org/stable/c/cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901a | kernel.org | Patch |
| https://git.kernel.org/stable/c/d4c4bd231ebad70e6f30db429e9640bf378b2f52 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.14, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |