PT-2026-94419 · Linux · Linux Kernel

CVE-2026-90071

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the sch teql scheduler where the teql master xmit() function sets the skb->dev variable to a slave device before calling ndo start xmit(), but fails to restore it if the transmission fails. This results in the socket buffer (skb) retaining a pointer to the previous slave when moving to the next one. If a subsequent slave lacks a resolved neighbour, teql resolve() passes the skb to neigh event send(), which queues it with a stale skb->dev reference. Since skb->dev does not hold a reference, deleting the previous slave frees the net device while the skb is still queued. Subsequent operations, such as arp error report() or neigh direct output(), lead to a Use-After-Free (UAF) condition, where the system attempts to access memory that has already been freed. A Use-After-Free is a memory corruption issue where an application continues to use a pointer after the memory it points to has been released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101894
CVE-2026-90071
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel