CVE-2026-23313 PUBLISHED

i40e: Fix preempt count leak in napi poll tracepoint

Assigner: Linux
Reserved: 13.01.2026 Published: 25.03.2026 Updated: 25.03.2026

In the Linux kernel, the following vulnerability has been resolved:

i40e: Fix preempt count leak in napi poll tracepoint

Using get_cpu() in the tracepoint assignment causes an obvious preempt count leak because nothing invokes put_cpu() to undo it:

softirq: huh, entered softirq 3 NET_RX with preempt_count 00000100, exited with 00000101?

This clearly has seen a lot of testing in the last 3+ years...

Use smp_processor_id() instead.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6d4d584a7ea8fc8d2be77545cb503118c193738a to b7e91827e1cf89cd34ad11dc8f8c010b70ab786e (excl.)
  • affected from 6d4d584a7ea8fc8d2be77545cb503118c193738a to 9e0f091821571f0da387462803ee42f0bb157582 (excl.)
  • affected from 6d4d584a7ea8fc8d2be77545cb503118c193738a to dca4ea596a3b0a1b82bc1d9f3e4d88bd9ad9561f (excl.)
  • affected from 6d4d584a7ea8fc8d2be77545cb503118c193738a to 4b3d54a85bd37ebf2d9836f0d0de775c0ff21af9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.2 is affected
  • unaffected from 0 to 6.2 (excl.)
  • unaffected from 6.12.77 to 6.12.* (incl.)
  • unaffected from 6.18.17 to 6.18.* (incl.)
  • unaffected from 6.19.7 to 6.19.* (incl.)
  • unaffected from 7.0-rc3 to * (incl.)

References