-
CVE-2026-64054
- EPSS 0.17%
- Veröffentlicht 19.07.2026 15:39:36
- Zuletzt bearbeitet 30.07.2026 14:59:47
- CVE-Watchlists
- Unerledigt
net: shaper: reject duplicate leaves in GROUP request
In the Linux kernel, the following vulnerability has been resolved: net: shaper: reject duplicate leaves in GROUP request net_shaper_nl_group_doit() does not deduplicate NET_SHAPER_A_LEAVES entries. When userspace supplies the same leaf handle twice, the same old-parent pointer lands twice in old_nodes[]. The cleanup loop double frees the parent. Of course the same parent may still be in old_nodes[] twice if we are moving multiple of its leaves. Note that this patch also implicitly fixes the fact that the i >= leaves_count path forgets to set ret.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e
Version <
5098b223f0f0c5c18a3884a8b0ea5bd4a0c7bd75
Status
affected
Version
5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e
Version <
31767bf852b59f05125b58a17007e4cd1ea9eb2e
Status
affected
Version
5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e
Version <
a9a2fa1da619f276580b0d4c5d12efac89e8642b
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.13
Status
affected
Version
0
Version <
6.13
Status
unaffected
Version <=
6.18.*
Version
6.18.34
Status
unaffected
Version <=
7.0.*
Version
7.0.11
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.062 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/5098b223f0f0c5c18a3884a8b0ea5bd4a0c7bd75
https://git.kernel.org/stable/c/31767bf852b59f05125b58a17007e4cd1ea9eb2e
https://git.kernel.org/stable/c/a9a2fa1da619f276580b0d4c5d12efac89e8642b