-

CVE-2026-98104

net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted

gen_new_kid() falls back to returning max (htid | 0xFFF) when both
idr_alloc_u32() ranges are full, instead of reporting an error.
u32_change() trusts that value and inserts a new knode with a handle
that is already live in the hash table, breaking handle uniqueness
within the table's node ID space.

The handle was never reserved in ht->handle_idr, so every later error
path that does idr_remove(&ht->handle_idr, handle) removes the
reservation of a different, live knode, which is then reused — one
failed add compounds into further duplicates.

The 4095 limit is per (table, bucket) — ht->handle_idr is per hash
table and the range is derived from htid (bucketid), so a table with
divisor 256 can legitimately hold 256*4095 knodes.

The sibling helper gen_new_htid() has the same silent in-band failure:
it returns 0 when the tp_c handle pool (1..0x7FF) is full, and
u32_init() publishes the root hash table with handle 0 without
checking.  Two root tables with handle 0 alias in u32_lookup_ht(),
allowing cross-tcf_proto knode add/lookup/delete.  Add the same
exhaustion check that the divisor path already has.

Return an error so u32_change() fails with ENOSPC/ENOMEM when the
node ID space is exhausted, and so u32_init() fails with -ENOMEM
when the hash table ID space is exhausted.  The extack message
distinguishes pool exhaustion (-ENOSPC) from a transient allocation
failure (-ENOMEM).

Conditions to recreate the bug:
- CONFIG_NET_SCHED=y, CONFIG_CLS_U32=y (or =m with module loaded)
- Create a clsact qdisc on a device, then add 4095 u32 filters with
  auto-generated handles to fill the node ID space for the root hash
  table (single bucket). The 4096th auto-handle filter add triggers
  the duplicate handle (fh 800::fff reused). Reachable at Level 2
  (unshare -Urn, namespace-local CAP_NET_ADMIN).
- For gen_new_htid: create 2047 u32 proto entries on the same block
  to fill the tp_c handle pool, then create one more. The root table
  gets handle 0 and aliases with other handle-0 root tables.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7801db8aec957fa6610efe0ee26a6c8bc0f1d73b
Version < f4ee13ed7f7b22dcd8287fcf477ae37bd84567da
Status affected
Version 7801db8aec957fa6610efe0ee26a6c8bc0f1d73b
Version < 84223baf21bc9b008444ae9bc38d5fb91fe00b9d
Status affected
Version 7801db8aec957fa6610efe0ee26a6c8bc0f1d73b
Version < 6890e28840bae4f6805e8de981c4ec8e12a4e064
Status affected
Version 7801db8aec957fa6610efe0ee26a6c8bc0f1d73b
Version < feab9261b537df4ebb8350e4779bc185373059fd
Status affected
Version 7801db8aec957fa6610efe0ee26a6c8bc0f1d73b
Version < f594f04268d01c5fdc975f3f51fc219ea2159ac6
Status affected
Version 7801db8aec957fa6610efe0ee26a6c8bc0f1d73b
Version < d7e7e98d23f42a92d9ab7e36302bd96bd9b33b5f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.16
Status affected
Version 0
Version < 3.16
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6890e28840bae4f6805e8de981c4ec8e12a4e064
https://git.kernel.org/stable/c/feab9261b537df4ebb8350e4779bc185373059fd
https://git.kernel.org/stable/c/f594f04268d01c5fdc975f3f51fc219ea2159ac6
https://git.kernel.org/stable/c/d7e7e98d23f42a92d9ab7e36302bd96bd9b33b5f
https://git.kernel.org/stable/c/84223baf21bc9b008444ae9bc38d5fb91fe00b9d
https://git.kernel.org/stable/c/f4ee13ed7f7b22dcd8287fcf477ae37bd84567da