-

CVE-2026-97959

net/sched: cls_route: free emptied bucket on filter move

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_route: free emptied bucket on filter move

route4_change can move an existing filter to a different top-level
bucket: route4_set_parms recomputes the handle from TCA_ROUTE4_TO/
FROM/IIF, and the handle-mismatch check is gated on the 'new' flag, so
for an existing filter the new handle may differ from the old one and
land in a different bucket. When this happens, the filter is unlinked
from the old bucket, but the bucket itself is never freed once it goes
empty. The stale empty bucket remains in head->table[], causing
route4_delete to report *last=false even after the last live filter is
gone. That pins the empty tcf_proto and causes a leak.

Fix this by refcounting the filters linked to a bucket and freeing the
bucket when the count drops to zero. The existing scan in route4_delete
goes away with it.

The count is updated at all sites that link or unlink a filter during add,
change and delete, and the bucket is dropped from head->table[] as soon as
it reaches zero.

Conditions to recreate the bug:
  CONFIG_NET_CLS_ROUTE4=y, CONFIG_NET_SCH_INGRESS=y, CONFIG_NET_CLS_ACT=y.

  tc qdisc replace dev lo clsact
  tc filter add dev lo ingress protocol ip pref 100 route from 1 to 1
  tc filter change dev lo ingress protocol ip pref 100 handle 0x10001 \
    route from 1 to 2
  tc filter del dev lo ingress protocol ip pref 100 handle 0x10002 \
    route from 1 to 2
  tc filter show dev lo ingress | grep -c 'pref 100 route chain 0 '
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < 9e7741b41a25b9d49df4d262fa314342e6f95c50
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < 48d38bf8c22a05fde07ba1f885cde27b851649a2
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < cc99d26b12431e4e4d0e346ec32764eb42c0aed9
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < 41e94079200aaf0cdbe4594b0af75710b33da124
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < 2e2f130951d34871b0643bf700164d97cff4b427
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < f8495d67434e1cb7e511297687ca55fdb28e4c20
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < 81dd117c04422c6d0c7974aba9fa6a0ba370959b
Status affected
Version 1e052be69d045c8d0f82ff1116fd3e5a79661745
Version < 1853f30cf5c84971f99788a76207c6f745380896
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.1
Status affected
Version 0
Version < 4.1
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2e2f130951d34871b0643bf700164d97cff4b427
https://git.kernel.org/stable/c/f8495d67434e1cb7e511297687ca55fdb28e4c20
https://git.kernel.org/stable/c/81dd117c04422c6d0c7974aba9fa6a0ba370959b
https://git.kernel.org/stable/c/1853f30cf5c84971f99788a76207c6f745380896
https://git.kernel.org/stable/c/41e94079200aaf0cdbe4594b0af75710b33da124
https://git.kernel.org/stable/c/48d38bf8c22a05fde07ba1f885cde27b851649a2
https://git.kernel.org/stable/c/9e7741b41a25b9d49df4d262fa314342e6f95c50
https://git.kernel.org/stable/c/cc99d26b12431e4e4d0e346ec32764eb42c0aed9