7.8

CVE-2026-74739

net/sched: cls_u32: skip hash tables in u32_bind_class()

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: skip hash tables in u32_bind_class()

u32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode
through the walker callback. u32_bind_class() unconditionally casts the
passed fh to tc_u_knode and accesses &n->res, so when fh is actually a
tc_u_hnode, which has no tcf_result member, this results in a
slab-out-of-bounds read of res->classid in tc_cls_bind_class().

The issue can be reproduced with the following commands:

    tc qdisc add dev lo root handle 1: hfsc
    tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit
    tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1
    tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit

Fix this by skipping hash tables via the TC_U32_KEY(handle) check.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1
Version < ec5f3005586a785689fd568361b0c5925cb1548b
Status affected
Version 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1
Version < 19d114b93c94bdef70496f26685c2a6b242f41b3
Status affected
Version 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1
Version < 594a064d603202b9ee21e07679d854e5c1750cc4
Status affected
Version 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1
Version < 31f26a95eeee926946809ac456c61a3217936a62
Status affected
Version 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1
Version < e71f8e9ed6f311410b14741f6012afe01869c0fa
Status affected
Version 07d79fc7d94e3f884b8b1c95aa615b202bb5e4c1
Version < 6d3724e616faf952c3adcf8414fc21a828ef3709
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.14
Status affected
Version 0
Version < 4.14
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.153
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.035
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ec5f3005586a785689fd568361b0c5925cb1548b
https://git.kernel.org/stable/c/19d114b93c94bdef70496f26685c2a6b242f41b3
https://git.kernel.org/stable/c/594a064d603202b9ee21e07679d854e5c1750cc4
https://git.kernel.org/stable/c/31f26a95eeee926946809ac456c61a3217936a62
https://git.kernel.org/stable/c/e71f8e9ed6f311410b14741f6012afe01869c0fa
https://git.kernel.org/stable/c/6d3724e616faf952c3adcf8414fc21a828ef3709