PT-2026-30144 · Linux+2 · Linux Kernel+2

CVE-2026-23449

·

Published

2026-04-03

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 7.0.0-rc3 through 7.0.0-rc3
Description The Linux kernel contains a flaw in the TEQL (Traffic Equation Queue Length) scheduler. Specifically, a double-free issue exists in the teql master xmit function when a TEQL device has a lockless Qdisc as its root. This can lead to crashes, as demonstrated by a KASAN (Kernel Address Sanitizer) report indicating a double-free in skb release data. The issue arises from failing to call qdisc reset with the seq lock to avoid racing with the datapath. The crash can occur during the destruction of the TEQL device, potentially triggered by operations like tc get qdisc or qdisc graft. The skb release data function is involved in the memory management of network packets (skbs), and the double-free corrupts memory, leading to system instability.
Recommendations Update to a newer kernel version that contains a fix for this vulnerability.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23449
ECHO-ED08-8447-8BE4
OESA-2026-2172
OESA-2026-2173
OESA-2026-2176
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:2068-1
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
SUSE-SU-2026:23261-1
SUSE-SU-2026:23262-1
SUSE-SU-2026:23263-1
SUSE-SU-2026:23264-1
SUSE-SU-2026:23265-1
SUSE-SU-2026:23266-1
SUSE-SU-2026:23267-1
SUSE-SU-2026:23268-1
SUSE-SU-2026:23269-1
SUSE-SU-2026:23270-1
SUSE-SU-2026:23271-1
SUSE-SU-2026:23272-1
SUSE-SU-2026:23282-1
SUSE-SU-2026:23283-1
SUSE-SU-2026:23284-1
SUSE-SU-2026:23285-1
SUSE-SU-2026:23286-1
SUSE-SU-2026:23287-1
SUSE-SU-2026:23288-1
SUSE-SU-2026:23290-1
SUSE-SU-2026:23291-1
SUSE-SU-2026:23292-1
SUSE-SU-2026:23293-1
SUSE-SU-2026:23296-1
SUSE-SU-2026:23331-1
SUSE-SU-2026:23332-1
SUSE-SU-2026:23333-1
SUSE-SU-2026:23334-1
SUSE-SU-2026:23335-1
SUSE-SU-2026:23336-1
SUSE-SU-2026:23337-1
SUSE-SU-2026:23338-1
SUSE-SU-2026:23339-1
SUSE-SU-2026:23340-1
SUSE-SU-2026:23341-1
SUSE-SU-2026:23343-1
SUSE-SU-2026:23366-1
SUSE-SU-2026:23367-1
SUSE-SU-2026:23368-1
SUSE-SU-2026:23369-1
SUSE-SU-2026:23370-1
SUSE-SU-2026:23371-1
SUSE-SU-2026:23372-1
SUSE-SU-2026:23373-1
SUSE-SU-2026:23374-1
SUSE-SU-2026:23375-1
SUSE-SU-2026:23376-1
SUSE-SU-2026:23377-1
SUSE-SU-2026:23378-1
SUSE-SU-2026:23383-1
SUSE-SU-2026:23384-1
SUSE-SU-2026:23385-1
SUSE-SU-2026:23386-1
SUSE-SU-2026:23387-1
SUSE-SU-2026:23388-1
SUSE-SU-2026:23389-1
SUSE-SU-2026:23390-1
SUSE-SU-2026:3689-1
SUSE-SU-2026:3694-1
SUSE-SU-2026:3696-1
SUSE-SU-2026:3697-1
SUSE-SU-2026:3698-1
SUSE-SU-2026:3702-1
SUSE-SU-2026:3703-1
SUSE-SU-2026:3704-1
SUSE-SU-2026:3706-1
SUSE-SU-2026:3707-1
SUSE-SU-2026:3708-1
SUSE-SU-2026:3709-1
SUSE-SU-2026:3710-1
SUSE-SU-2026:3715-1
SUSE-SU-2026:3719-1
SUSE-SU-2026:3722-1
SUSE-SU-2026:3723-1
SUSE-SU-2026:3724-1
SUSE-SU-2026:3726-1
SUSE-SU-2026:3728-1
SUSE-SU-2026:3739-1
SUSE-SU-2026:3740-1
SUSE-SU-2026:3743-1
SUSE-SU-2026:3744-1
SUSE-SU-2026:3746-1
SUSE-SU-2026:3747-1
SUSE-SU-2026:3748-1
SUSE-SU-2026:3750-1
SUSE-SU-2026:3754-1
SUSE-SU-2026:3756-1
SUSE-SU-2026:3760-1
SUSE-SU-2026:3761-1
SUSE-SU-2026:3766-1
SUSE-SU-2026:3768-1
SUSE-SU-2026:3770-1
SUSE-SU-2026:3771-1
SUSE-SU-2026:3774-1
SUSE-SU-2026:3826-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu