Back

CRITICAL

net: mana: Fix race on per-CQ variable napi work_done

Published Oct 21, 2024

Description

After calling napi_complete_done(), the NAPIF_STATE_SCHED bit may be cleared, and another CPU can start napi thread and access per-CQ variable, cq->work_done. If the other thread (for example, from busy_poll) sets it to a value >= budget, this thread will continue to run when it should stop, and cause memory corruption and panic.

To fix this issue, save the per-CQ work_done variable in a local variable before napi_complete_done(), so it won't be corrupted by a possible concurrent thread after napi_complete_done().

Also, add a flag bit to advertise to the NIC firmware: the NAPI work_done variable race is fixed, so the driver is able to reliably support features like busy_poll.

Affected products

Remediation

Red Hat statement

The fail could happen for the specific cases (race condition) during this network driver usage. No known attack vectors (apart from possibility of deny of service). The driver enabled only in latest versions of Red Hat Enterprise Linux (8.9 or 9.5).

Red Hat mitigation

To mitigate this issue, prevent module mana from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024