{"api_version":"1","generated_at":"2026-09-21T20:51:14+00:00","cve":"CVE-2026-90232","urls":{"html":"https://cve.report/CVE-2026-90232","api":"https://cve.report/api/cve/CVE-2026-90232.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90232","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90232"},"summary":{"title":"amt: Don't support cross-netns setup.","description":"In the Linux kernel, the following vulnerability has been resolved:\n\namt: Don't support cross-netns setup.\n\nWhen a lower device is unregistered, amt_device_event() tries\nto unregister its upper AMT device, but it has two problems.\n\n  1. amt_lookup_upper_dev() looks up an upper device in the\n      lower device's netns only\n\n  2. amt_device_event() unregisters a single upper device only\n\nIf AMT device is created on a lower device in another netns,\nremoving the lower device triggers the splat below and gets\nstuck until all upper devices are removed. [0]\n\nThe cross-netns setup seems unintentional considering 1. and\nthe following points:\n\n  * amt_link_setup() sets dev->netns_immutable to true\n  * skb_scrub_packet() is not called in the fast path\n  * iproute2 binary fails to find cross-netns lower device via\n    link-netns:\n      # ip -n ns1 link add amt0 link-netns ns2 type amt dev veth1\n      Cannot find device \"veth1\"\n\nInstead of supporting it properly and preparing for per-netns\nnetdev unreg, let's forbid cross-netns setup.\n\nNote that the problem 2. needs a separate fix.\n\n[0]:\nWARNING: net/core/dev.c:12518 at unregister_netdevice_many_notify+0x1cce/0x2250, CPU#48: ip/2031\nModules linked in:\nCPU: 48 UID: 0 PID: 2031 Comm: ip Not tainted 7.2.0-rc5+ #27 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nRIP: 0010:unregister_netdevice_many_notify (net/core/dev.c:12518)\nCode: 89 ef e8 d5 52 ae fe e9 d0 f4 ff ff 48 8d 3d f9 3b 9c 02 48 c7 c6 c0 0b 63 84 ba ab 1f 00 00 67 48 0f b9 3a e9 65 ff ff ff 90 <0f> 0b 90 eb 81 48 8d 3d f6 3b 9c 02 48 c7 c6 c0 0b 63 84 ba e2 1f\nRSP: 0018:ffffc90004abf160 EFLAGS: 00010212\nRAX: ffff888104d38260 RBX: ffff88800b0911b8 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff85b9f880\nRBP: ffffc90004abf2d0 R08: ffffffff85b9f887 R09: 1ffffffff0b73f10\nR10: dffffc0000000000 R11: fffffbfff0b73f11 R12: ffff88800b091d08\nR13: ffff88800b091178 R14: dffffc0000000000 R15: ffff88800b091000\nFS:  00007f555b86c600(0000) GS:ffff8881942a0000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000562107d489c0 CR3: 0000000109a40002 CR4: 0000000000372ef0\nCall Trace:\n <TASK>\n rtnl_dellink (net/core/rtnetlink.c:3632 net/core/rtnetlink.c:3674)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7112)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1319)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n ____sys_sendmsg (net/socket.c:775)\n __sys_sendmsg (net/socket.c:2738)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n...\nunregister_netdevice: waiting for veth0 to become free. Usage count = 7\nref_tracker: netdev@ffff88800d7496d8 has 3/3 users at\n     __netdev_adjacent_dev_insert (./include/linux/netdevice.h:4525 ./include/linux/netdevice.h:4554 net/core/dev.c:8791)\n     __netdev_upper_dev_link (net/core/dev.c:8879 net/core/dev.c:8963)\n     netdev_upper_dev_link (net/core/dev.c:9009)\n     amt_newlink (drivers/net/amt.c:3321)","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:19","updated_at":"2026-09-17 17:17:19"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06","name":"https://git.kernel.org/stable/c/e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e1dc0af719a2566ae7ccb82c0a11f70aa54908e9","name":"https://git.kernel.org/stable/c/e1dc0af719a2566ae7ccb82c0a11f70aa54908e9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/569eb11f0990849ba48706a2bfa743273707e254","name":"https://git.kernel.org/stable/c/569eb11f0990849ba48706a2bfa743273707e254","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90232","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90232","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b9022b53adad88fd6cf2b9718c9e498504f3e1dd 569eb11f0990849ba48706a2bfa743273707e254 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b9022b53adad88fd6cf2b9718c9e498504f3e1dd e1dc0af719a2566ae7ccb82c0a11f70aa54908e9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b9022b53adad88fd6cf2b9718c9e498504f3e1dd e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/amt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"569eb11f0990849ba48706a2bfa743273707e254","status":"affected","version":"b9022b53adad88fd6cf2b9718c9e498504f3e1dd","versionType":"git"},{"lessThan":"e1dc0af719a2566ae7ccb82c0a11f70aa54908e9","status":"affected","version":"b9022b53adad88fd6cf2b9718c9e498504f3e1dd","versionType":"git"},{"lessThan":"e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06","status":"affected","version":"b9022b53adad88fd6cf2b9718c9e498504f3e1dd","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/amt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.16"},{"lessThan":"5.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\namt: Don't support cross-netns setup.\n\nWhen a lower device is unregistered, amt_device_event() tries\nto unregister its upper AMT device, but it has two problems.\n\n  1. amt_lookup_upper_dev() looks up an upper device in the\n      lower device's netns only\n\n  2. amt_device_event() unregisters a single upper device only\n\nIf AMT device is created on a lower device in another netns,\nremoving the lower device triggers the splat below and gets\nstuck until all upper devices are removed. [0]\n\nThe cross-netns setup seems unintentional considering 1. and\nthe following points:\n\n  * amt_link_setup() sets dev->netns_immutable to true\n  * skb_scrub_packet() is not called in the fast path\n  * iproute2 binary fails to find cross-netns lower device via\n    link-netns:\n      # ip -n ns1 link add amt0 link-netns ns2 type amt dev veth1\n      Cannot find device \"veth1\"\n\nInstead of supporting it properly and preparing for per-netns\nnetdev unreg, let's forbid cross-netns setup.\n\nNote that the problem 2. needs a separate fix.\n\n[0]:\nWARNING: net/core/dev.c:12518 at unregister_netdevice_many_notify+0x1cce/0x2250, CPU#48: ip/2031\nModules linked in:\nCPU: 48 UID: 0 PID: 2031 Comm: ip Not tainted 7.2.0-rc5+ #27 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nRIP: 0010:unregister_netdevice_many_notify (net/core/dev.c:12518)\nCode: 89 ef e8 d5 52 ae fe e9 d0 f4 ff ff 48 8d 3d f9 3b 9c 02 48 c7 c6 c0 0b 63 84 ba ab 1f 00 00 67 48 0f b9 3a e9 65 ff ff ff 90 <0f> 0b 90 eb 81 48 8d 3d f6 3b 9c 02 48 c7 c6 c0 0b 63 84 ba e2 1f\nRSP: 0018:ffffc90004abf160 EFLAGS: 00010212\nRAX: ffff888104d38260 RBX: ffff88800b0911b8 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff85b9f880\nRBP: ffffc90004abf2d0 R08: ffffffff85b9f887 R09: 1ffffffff0b73f10\nR10: dffffc0000000000 R11: fffffbfff0b73f11 R12: ffff88800b091d08\nR13: ffff88800b091178 R14: dffffc0000000000 R15: ffff88800b091000\nFS:  00007f555b86c600(0000) GS:ffff8881942a0000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000562107d489c0 CR3: 0000000109a40002 CR4: 0000000000372ef0\nCall Trace:\n <TASK>\n rtnl_dellink (net/core/rtnetlink.c:3632 net/core/rtnetlink.c:3674)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7112)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1319)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n ____sys_sendmsg (net/socket.c:775)\n __sys_sendmsg (net/socket.c:2738)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n...\nunregister_netdevice: waiting for veth0 to become free. Usage count = 7\nref_tracker: netdev@ffff88800d7496d8 has 3/3 users at\n     __netdev_adjacent_dev_insert (./include/linux/netdevice.h:4525 ./include/linux/netdevice.h:4554 net/core/dev.c:8791)\n     __netdev_upper_dev_link (net/core/dev.c:8879 net/core/dev.c:8963)\n     netdev_upper_dev_link (net/core/dev.c:9009)\n     amt_newlink (drivers/net/amt.c:3321)"}],"providerMetadata":{"dateUpdated":"2026-09-17T16:07:39.279Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/569eb11f0990849ba48706a2bfa743273707e254"},{"url":"https://git.kernel.org/stable/c/e1dc0af719a2566ae7ccb82c0a11f70aa54908e9"},{"url":"https://git.kernel.org/stable/c/e99ecc3046ea5f5c6b5e1f8b4ef854c6c6998e06"}],"title":"amt: Don't support cross-netns setup.","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90232","datePublished":"2026-09-17T16:07:39.279Z","dateReserved":"2026-09-11T19:38:34.794Z","dateUpdated":"2026-09-17T16:07:39.279Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:19","lastModifiedDate":"2026-09-17 17:17:19","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90232","Ordinal":"1","Title":"amt: Don't support cross-netns setup.","CVE":"CVE-2026-90232","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90232","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\namt: Don't support cross-netns setup.\n\nWhen a lower device is unregistered, amt_device_event() tries\nto unregister its upper AMT device, but it has two problems.\n\n  1. amt_lookup_upper_dev() looks up an upper device in the\n      lower device's netns only\n\n  2. amt_device_event() unregisters a single upper device only\n\nIf AMT device is created on a lower device in another netns,\nremoving the lower device triggers the splat below and gets\nstuck until all upper devices are removed. [0]\n\nThe cross-netns setup seems unintentional considering 1. and\nthe following points:\n\n  * amt_link_setup() sets dev->netns_immutable to true\n  * skb_scrub_packet() is not called in the fast path\n  * iproute2 binary fails to find cross-netns lower device via\n    link-netns:\n      # ip -n ns1 link add amt0 link-netns ns2 type amt dev veth1\n      Cannot find device \"veth1\"\n\nInstead of supporting it properly and preparing for per-netns\nnetdev unreg, let's forbid cross-netns setup.\n\nNote that the problem 2. needs a separate fix.\n\n[0]:\nWARNING: net/core/dev.c:12518 at unregister_netdevice_many_notify+0x1cce/0x2250, CPU#48: ip/2031\nModules linked in:\nCPU: 48 UID: 0 PID: 2031 Comm: ip Not tainted 7.2.0-rc5+ #27 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nRIP: 0010:unregister_netdevice_many_notify (net/core/dev.c:12518)\nCode: 89 ef e8 d5 52 ae fe e9 d0 f4 ff ff 48 8d 3d f9 3b 9c 02 48 c7 c6 c0 0b 63 84 ba ab 1f 00 00 67 48 0f b9 3a e9 65 ff ff ff 90 <0f> 0b 90 eb 81 48 8d 3d f6 3b 9c 02 48 c7 c6 c0 0b 63 84 ba e2 1f\nRSP: 0018:ffffc90004abf160 EFLAGS: 00010212\nRAX: ffff888104d38260 RBX: ffff88800b0911b8 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff85b9f880\nRBP: ffffc90004abf2d0 R08: ffffffff85b9f887 R09: 1ffffffff0b73f10\nR10: dffffc0000000000 R11: fffffbfff0b73f11 R12: ffff88800b091d08\nR13: ffff88800b091178 R14: dffffc0000000000 R15: ffff88800b091000\nFS:  00007f555b86c600(0000) GS:ffff8881942a0000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000562107d489c0 CR3: 0000000109a40002 CR4: 0000000000372ef0\nCall Trace:\n <TASK>\n rtnl_dellink (net/core/rtnetlink.c:3632 net/core/rtnetlink.c:3674)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7112)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1319)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n ____sys_sendmsg (net/socket.c:775)\n __sys_sendmsg (net/socket.c:2738)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n...\nunregister_netdevice: waiting for veth0 to become free. Usage count = 7\nref_tracker: netdev@ffff88800d7496d8 has 3/3 users at\n     __netdev_adjacent_dev_insert (./include/linux/netdevice.h:4525 ./include/linux/netdevice.h:4554 net/core/dev.c:8791)\n     __netdev_upper_dev_link (net/core/dev.c:8879 net/core/dev.c:8963)\n     netdev_upper_dev_link (net/core/dev.c:9009)\n     amt_newlink (drivers/net/amt.c:3321)","Type":"Description","Title":"amt: Don't support cross-netns setup."}]}}}