PT-2026-94419 · Linux · Linux Kernel
CVE-2026-90071
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
sch teql scheduler where the teql master xmit() function sets the skb->dev variable to a slave device before calling ndo start xmit(), but fails to restore it if the transmission fails. This results in the socket buffer (skb) retaining a pointer to the previous slave when moving to the next one. If a subsequent slave lacks a resolved neighbour, teql resolve() passes the skb to neigh event send(), which queues it with a stale skb->dev reference. Since skb->dev does not hold a reference, deleting the previous slave frees the net device while the skb is still queued. Subsequent operations, such as arp error report() or neigh direct output(), lead to a Use-After-Free (UAF) condition, where the system attempts to access memory that has already been freed. A Use-After-Free is a memory corruption issue where an application continues to use a pointer after the memory it points to has been released.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel