Improper control of a resource through its lifetime in Linux kernel - CVE-2026-97434
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause active NAPI instances to be deleted.
The vulnerability exists due to improper resource lifecycle management in the dpaa2-switch device removal path when removing a DPSW device. A local privileged user can trigger the device removal path to cause active NAPI instances to be deleted.
All NAPI instances are attached to the first switch port's net_device but are shared by all switch ports.