PT-2026-108766 · Linux · Linux
CVE-2026-98380
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/sched: reject IDR error pointers when deleting actions
tcf action delete() drops the reference held by its lookup before calling
tcf idr delete index() with the saved action index. An unlocked
classifier can remove that action and reserve the same IDR slot with
ERR PTR(-EBUSY) in between.
tcf idr delete index() only checks the lookup result for NULL. It
therefore treats the reservation as a tc action and dereferences
tcfa bindcnt. A hardware execution breakpoint was used to schedule the
interleaving without changing the kernel source. KASAN reported this
decoded trace:
BUG: KASAN: null-ptr-deref in tca action gd+0x5b9/0x1010
Read of size 4 at addr 0000000000000010 by task poc/150
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002
RIP: tca action gd+0x5c0/0x1010:
arch atomic read at arch/x86/include/asm/atomic.h:23
raw atomic read at include/linux/atomic/atomic-arch-fallback.h:457
atomic read at include/linux/atomic/atomic-instrumented.h:33
tcf idr delete index at net/sched/act api.c:766
tcf action delete at net/sched/act api.c:1859
tcf del notify at net/sched/act api.c:2014
tca action gd at net/sched/act api.c:2064
R13: 0000000000000010 R15: fffffffffffffff0
Kernel panic - not syncing: Fatal exception
R15 contains ERR PTR(-EBUSY), and adding the tcfa bindcnt offset produces
the address in R13. With the guard applied, the same reproducer returned
-ENOENT without a KASAN report or panic. Treat error pointers as absent
and return -ENOENT.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux