CVE-2026-98017

Summary

In the Linux kernel, the following vulnerability has been resolved:

net/sched: defer qdisc freeing after failed creation

An RTM_NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini_Qdisc to lockless readers. If the same request has an invalid TCA_RATE, estimator setup fails after ->init(); the unwind removes the pointer but synchronously frees its containing qdisc while tc_run() may still hold it.

Retire failed qdiscs through the same RCU helper as normal destruction. Inline the synchronous free into the callback now that no direct callers remain.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux51ab2994c387c80b45caf8b8067b3f3b97771d25 < 20bf6fa34b345333971bd4464a322cce87b83f4eaffected
LinuxLinux51ab2994c387c80b45caf8b8067b3f3b97771d25 < 156a3bab69744e9225bb9eff8c5cc53da18d5a2eaffected
LinuxLinux51ab2994c387c80b45caf8b8067b3f3b97771d25 < 5bfe927c5b4b290fad529186218c728589b4b101affected
LinuxLinux51ab2994c387c80b45caf8b8067b3f3b97771d25 < e6662f2100f8d33b0f4d0047c219efd6bba186eaaffected
LinuxLinux4.16affected
LinuxLinux0 < 4.16unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References