PT-2026-108766 · Linux · Linux
CVE-2026-98380
·
Publicado
2026-10-09
·
Atualizado
2026-10-09
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net/sched: reject IDR error pointers when deleting actions
tcf action delete() drops the reference held by its lookup before calling
tcf idr delete index() with the saved action index. An unlocked
classifier can remove that action and reserve the same IDR slot with
ERR PTR(-EBUSY) in between.
tcf idr delete index() only checks the lookup result for NULL. It
therefore treats the reservation as a tc action and dereferences
tcfa bindcnt. A hardware execution breakpoint was used to schedule the
interleaving without changing the kernel source. KASAN reported this
decoded trace:
BUG: KASAN: null-ptr-deref in tca action gd+0x5b9/0x1010
Read of size 4 at addr 0000000000000010 by task poc/150
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002
RIP: tca action gd+0x5c0/0x1010:
arch atomic read at arch/x86/include/asm/atomic.h:23
raw atomic read at include/linux/atomic/atomic-arch-fallback.h:457
atomic read at include/linux/atomic/atomic-instrumented.h:33
tcf idr delete index at net/sched/act api.c:766
tcf action delete at net/sched/act api.c:1859
tcf del notify at net/sched/act api.c:2014
tca action gd at net/sched/act api.c:2064
R13: 0000000000000010 R15: fffffffffffffff0
Kernel panic - not syncing: Fatal exception
R15 contains ERR PTR(-EBUSY), and adding the tcfa bindcnt offset produces
the address in R13. With the guard applied, the same reproducer returned
-ENOENT without a KASAN report or panic. Treat error pointers as absent
and return -ENOENT.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux