PT-2026-98680 · Linux · Linux

CVE-2026-98017

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
net/sched: defer qdisc freeing after failed creation
An RTM NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini Qdisc to lockless readers. If the same request has an invalid TCA RATE, estimator setup fails after ->init(); the unwind removes the pointer but synchronously frees its containing qdisc while tc run() may still hold it.
Retire failed qdiscs through the same RCU helper as normal destruction. Inline the synchronous free into the callback now that no direct callers remain.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98017

Produtos afetados

Linux