-

CVE-2026-90248

net/sched: cls_api: fix teardown of an adopted proto on insert-race loss

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_api: fix teardown of an adopted proto on insert-race loss

In tc_new_tfilter() the create branch sets tp_created = 1 before calling
tcf_chain_tp_insert_unique(). When the caller loses the race (another
request inserted a proto at the same chain/prio first), insert_unique()
destroys the caller's own tp_new and returns the winner's proto with an
extra reference. tp_created was never cleared, so the loser's errout
path treated the winner's live proto as its own and called
tcf_chain_tp_delete_empty() on it, silently unlinking an active
classifier that the winning request already advertised via
RTM_NEWTFILTER.

Track the outcome of the insert step in a single tri-state variable so
each errout path reacts correctly:

- TP_NOT_CREATED: no proto created; pursue the old path.
- TP_CREATED: proto inserted successfully; same code path as before.
- TP_NOT_OWNED: New - lost the insert race; tp is another request's proto
  (chain ref already released by tp_new's destroy)

Both errout reactions are single expressions derived from the state.

This fix is motivated by the Sashiko's automated review of Patch
(net/sched: cls_api: Always acquire rtnl_lock when destroying locked
classifiers) [1][2]. The review identified the silent-unlink behaviour of
an adopted proto's teardown when a request loses the
tcf_chain_tp_insert_unique() race.

[1] https://sashiko.dev/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
[2] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < a68e664ddf16ecae6d769d6a2eb356f8abab75c9
Status affected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < df02b6dc136af45e92ee4c86f4aa6c9a60790b1e
Status affected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < bee2208276c8e0e40a249ffdcf6e5434a79a847c
Status affected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < 219c87aeefdcc8c1caf28cc99e9b361ce7393d3a
Status affected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < bbe2fd6d77df630356185406a97317f6aa6a92cf
Status affected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < dc8b33b819cb02a75936940c120aa669ad89942d
Status affected
Version 8b64678e0af8f4d62a40149baedebe78503a5255
Version < d4e359b3608a0e184bbe8d61a5c3b50d0831c44a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.1
Status affected
Version 0
Version < 5.1
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a68e664ddf16ecae6d769d6a2eb356f8abab75c9
https://git.kernel.org/stable/c/df02b6dc136af45e92ee4c86f4aa6c9a60790b1e
https://git.kernel.org/stable/c/bee2208276c8e0e40a249ffdcf6e5434a79a847c
https://git.kernel.org/stable/c/219c87aeefdcc8c1caf28cc99e9b361ce7393d3a
https://git.kernel.org/stable/c/bbe2fd6d77df630356185406a97317f6aa6a92cf
https://git.kernel.org/stable/c/dc8b33b819cb02a75936940c120aa669ad89942d
https://git.kernel.org/stable/c/d4e359b3608a0e184bbe8d61a5c3b50d0831c44a