7.8

CVE-2026-23270

net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks

In the Linux kernel, the following vulnerability has been resolved:

net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks

As Paolo said earlier [1]:

"Since the blamed commit below, classify can return TC_ACT_CONSUMED while
the current skb being held by the defragmentation engine. As reported by
GangMin Kim, if such packet is that may cause a UaF when the defrag engine
later on tries to tuch again such packet."

act_ct was never meant to be used in the egress path, however some users
are attaching it to egress today [2]. Attempting to reach a middle
ground, we noticed that, while most qdiscs are not handling
TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we
address the issue by only allowing act_ct to bind to clsact/ingress
qdiscs and shared blocks. That way it's still possible to attach act_ct to
egress (albeit only with clsact).

[1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/
[2] https://lore.kernel.org/netdev/cc6bfb4a-4a2b-42d8-b9ce-7ef6644fb22b@ovn.org/
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.15.148 < 5.15.203
Linux ≫ Linux Kernel Version >= 6.1.75 < 6.1.167
Linux ≫ Linux Kernel Version >= 6.6.14 < 6.6.130
Linux ≫ Linux Kernel Version >= 6.7.2 < 6.8
Linux ≫ Linux Kernel Version >= 6.8 < 6.12.77
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.18
Linux ≫ Linux Kernel Version >= 6.19 < 6.19.8
Linux ≫ Linux Kernel Version 7.0 Update rc1
Linux ≫ Linux Kernel Version 7.0 Update rc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.026
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://git.kernel.org/stable/c/524ce8b4ea8f64900b6c52b6a28df74f6bc0801e
Patch
https://git.kernel.org/stable/c/380ad8b7c65ea7aa10ef2258297079ed5ac1f5b6
Patch
https://git.kernel.org/stable/c/9deda0fcda5c1f388c5e279541850b71a2ccfcf4
Patch
https://git.kernel.org/stable/c/11cb63b0d1a0685e0831ae3c77223e002ef18189
Patch
https://git.kernel.org/stable/c/5a110ddcc99bda77a28598b3555fe009eaab3828
Patch
https://git.kernel.org/stable/c/fb3c380a54e33d1fd272cc342faa906d787d7ef1
Patch
https://git.kernel.org/stable/c/bc4e5bb529823a09f02dbe96169de679a9db26e0
Patch
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
https://cert-portal.siemens.com/productcert/html/ssa-019113.html