Not scored yet

CVE-2026-90113

In the Linux kernel, the following vulnerability has been resolved: netdevsim: update queue NAPI association on queue reset In netdevsim, receive queues (struct nsim_rq) embed their own struct napi_struct. When queue reset is performed (e.g. via queue_reset debugfs), nsim_queue_start() swaps in a newly allocated struct nsim_rq, and nsim_queue_mem_free() later deletes and frees the old one. However, nsim_queue_start() failed to update the queue-to-NAPI mapping via netif_queue_set_napi(). As a result, dev->_rx[idx].napi continued to point to the old NAPI struct. After the old queue was freed, a subsequent queue dump via Netlink (NETDEV_CMD_QUEUE_GET) triggered a KASAN slab-use-after-free read in nla_put_napi_id() when accessing rxq->napi->napi_id. Fix this by calling netif_queue_set_napi() in nsim_queue_start() to associate the new NAPI with the RX queue, and clear the association with netif_queue_set_napi(..., NULL) in nsim_del_napi() during teardown.

What this means for your business

    What to do

    1. 1Ask your IT team or provider whether any of your systems use the affected product.
    2. 2If you do, follow the vendor's guidance. No patch reference has been published yet.

    Not sure if your company is exposed?

    Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.

    Scoring

    CVSS
    Not yet scored
    Assigned by
    416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Dates

    Published
    2026-09-17
    Last modified
    2026-09-17
    Sources
    NVD

    References