-

CVE-2026-98380

net/sched: reject IDR error pointers when deleting actions

In the Linux kernel, the following vulnerability has been resolved:

net/sched: reject IDR error pointers when deleting actions

tcf_action_delete() drops the reference held by its lookup before calling
tcf_idr_delete_index() with the saved action index.  An unlocked
classifier can remove that action and reserve the same IDR slot with
ERR_PTR(-EBUSY) in between.

tcf_idr_delete_index() only checks the lookup result for NULL.  It
therefore treats the reservation as a tc_action and dereferences
tcfa_bindcnt.  A hardware execution breakpoint was used to schedule the
interleaving without changing the kernel source.  KASAN reported this
decoded trace:

  BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010
  Read of size 4 at addr 0000000000000010 by task poc/150
  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002
  RIP: tca_action_gd+0x5c0/0x1010:
    arch_atomic_read at arch/x86/include/asm/atomic.h:23
    raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457
    atomic_read at include/linux/atomic/atomic-instrumented.h:33
    tcf_idr_delete_index at net/sched/act_api.c:766
    tcf_action_delete at net/sched/act_api.c:1859
    tcf_del_notify at net/sched/act_api.c:2014
    tca_action_gd at net/sched/act_api.c:2064
  R13: 0000000000000010 R15: fffffffffffffff0
  Kernel panic - not syncing: Fatal exception

R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces
the address in R13.  With the guard applied, the same reproducer returned
-ENOENT without a KASAN report or panic.  Treat error pointers as absent
and return -ENOENT.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < 39b751a210bf61a374afa82749afc7a77a08bf1d
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < dd80a7519824b72c8fcfd3cc50cb93f7e2d90923
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < 6bf076258aac4e0af69ef317656c31ce6444d647
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < 6c9f07bf8800171de2cd3f02815cebe1f4d45f2d
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < 259caa711b7688365676442e2fdb286b8aceaa80
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < 968550a439f64bd1a6c0d88efb92e4f082f84a26
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < a9551f26287debe6d8aa6e8841974661065b975f
Status affected
Version 0190c1d452a91c38a3462abdd81752be1b9006a8
Version < c82b797abe668d0b668601a93ba2c0b071a63574
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.19
Status affected
Version 0
Version < 4.19
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.55
Status unaffected
Version <= 7.2.*
Version 7.2.9
Status unaffected
Version <= *
Version 7.3-rc5
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.067
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/39b751a210bf61a374afa82749afc7a77a08bf1d
https://git.kernel.org/stable/c/dd80a7519824b72c8fcfd3cc50cb93f7e2d90923
https://git.kernel.org/stable/c/6bf076258aac4e0af69ef317656c31ce6444d647
https://git.kernel.org/stable/c/6c9f07bf8800171de2cd3f02815cebe1f4d45f2d
https://git.kernel.org/stable/c/259caa711b7688365676442e2fdb286b8aceaa80
https://git.kernel.org/stable/c/968550a439f64bd1a6c0d88efb92e4f082f84a26
https://git.kernel.org/stable/c/a9551f26287debe6d8aa6e8841974661065b975f
https://git.kernel.org/stable/c/c82b797abe668d0b668601a93ba2c0b071a63574