PT-2026-108766 · Linux · Linux

CVE-2026-98380

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/sched: reject IDR error pointers when deleting actions
tcf action delete() drops the reference held by its lookup before calling tcf idr delete index() with the saved action index. An unlocked classifier can remove that action and reserve the same IDR slot with ERR PTR(-EBUSY) in between.
tcf idr delete index() only checks the lookup result for NULL. It therefore treats the reservation as a tc action and dereferences tcfa bindcnt. A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source. KASAN reported this decoded trace:
BUG: KASAN: null-ptr-deref in tca action gd+0x5b9/0x1010 Read of size 4 at addr 0000000000000010 by task poc/150 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002 RIP: tca action gd+0x5c0/0x1010: arch atomic read at arch/x86/include/asm/atomic.h:23 raw atomic read at include/linux/atomic/atomic-arch-fallback.h:457 atomic read at include/linux/atomic/atomic-instrumented.h:33 tcf idr delete index at net/sched/act api.c:766 tcf action delete at net/sched/act api.c:1859 tcf del notify at net/sched/act api.c:2014 tca action gd at net/sched/act api.c:2064 R13: 0000000000000010 R15: fffffffffffffff0 Kernel panic - not syncing: Fatal exception
R15 contains ERR PTR(-EBUSY), and adding the tcfa bindcnt offset produces the address in R13. With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic. Treat error pointers as absent and return -ENOENT.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98380

Affected Products

Linux