7.8
CVE-2026-53011
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:29:22
- Zuletzt bearbeitet 14.07.2026 18:24:16
- CVE-Watchlists
- Unerledigt
net/sched: taprio: fix use-after-free in advance_sched() on schedule switch
In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch In advance_sched(), when should_change_schedules() returns true, switch_schedules() is called to promote the admin schedule to oper. switch_schedules() queues the old oper schedule for RCU freeing via call_rcu(), but 'next' still points into an entry of the old oper schedule. The subsequent 'next->end_time = end_time' and rcu_assign_pointer(q->current_entry, next) are use-after-free. Fix this by selecting 'next' from the new oper schedule immediately after switch_schedules(), and using its pre-calculated end_time. setup_first_end_time() sets the first entry's end_time to base_time + interval when the schedule is installed, so the value is already correct. The deleted 'end_time = sched_base_time(admin)' assignment was also harmful independently: it would overwrite the new first entry's pre-calculated end_time with just base_time.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.2 < 5.10.258
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.209
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.175
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.141
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.91
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.33
Linux ≫ Linux Kernel Version >= 6.19 < 7.0.10
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.026 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://git.kernel.org/stable/c/a8fc396519ef4f081bc545e88f61241728bb78d7
https://git.kernel.org/stable/c/3471874578160a28c171a607fa069f24062634b8
https://git.kernel.org/stable/c/7256996e1ef553716817f3bfd077c2f3b48b582f
https://git.kernel.org/stable/c/eee072fe16c646190d33ae69c9983d8de1562bf8
https://git.kernel.org/stable/c/1bd286fa3e21200133478ed523cc6a2788baf38a
https://git.kernel.org/stable/c/b73235da5dde77ed1264f9767b62c28c9d71fd78
https://git.kernel.org/stable/c/0e62171df8ed4804d00db088f17eed06468233fa
https://git.kernel.org/stable/c/105425b1969c5affe532713cfac1c0b320d7ac2b