๐Ÿ” CVE Alert

CVE-2026-98380

UNKNOWN 0.0

net/sched: reject IDR error pointers when deleting actions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: reject IDR error pointers when deleting actions tcf_action_delete() drops the reference held by its lookup before calling tcf_idr_delete_index() with the saved action index. An unlocked classifier can remove that action and reserve the same IDR slot with ERR_PTR(-EBUSY) in between. tcf_idr_delete_index() only checks the lookup result for NULL. It therefore treats the reservation as a tc_action and dereferences tcfa_bindcnt. A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source. KASAN reported this decoded trace: BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010 Read of size 4 at addr 0000000000000010 by task poc/150 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002 RIP: tca_action_gd+0x5c0/0x1010: arch_atomic_read at arch/x86/include/asm/atomic.h:23 raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457 atomic_read at include/linux/atomic/atomic-instrumented.h:33 tcf_idr_delete_index at net/sched/act_api.c:766 tcf_action_delete at net/sched/act_api.c:1859 tcf_del_notify at net/sched/act_api.c:2014 tca_action_gd at net/sched/act_api.c:2064 R13: 0000000000000010 R15: fffffffffffffff0 Kernel panic - not syncing: Fatal exception R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces the address in R13. With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic. Treat error pointers as absent and return -ENOENT.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0190c1d452a91c38a3462abdd81752be1b9006a8 < 39b751a210bf61a374afa82749afc7a77a08bf1d 0190c1d452a91c38a3462abdd81752be1b9006a8 < dd80a7519824b72c8fcfd3cc50cb93f7e2d90923 0190c1d452a91c38a3462abdd81752be1b9006a8 < 6bf076258aac4e0af69ef317656c31ce6444d647 0190c1d452a91c38a3462abdd81752be1b9006a8 < 6c9f07bf8800171de2cd3f02815cebe1f4d45f2d 0190c1d452a91c38a3462abdd81752be1b9006a8 < 259caa711b7688365676442e2fdb286b8aceaa80 0190c1d452a91c38a3462abdd81752be1b9006a8 < 968550a439f64bd1a6c0d88efb92e4f082f84a26 0190c1d452a91c38a3462abdd81752be1b9006a8 < a9551f26287debe6d8aa6e8841974661065b975f 0190c1d452a91c38a3462abdd81752be1b9006a8 < c82b797abe668d0b668601a93ba2c0b071a63574
Linux / Linux
4.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/39b751a210bf61a374afa82749afc7a77a08bf1d git.kernel.org: https://git.kernel.org/stable/c/dd80a7519824b72c8fcfd3cc50cb93f7e2d90923 git.kernel.org: https://git.kernel.org/stable/c/6bf076258aac4e0af69ef317656c31ce6444d647 git.kernel.org: https://git.kernel.org/stable/c/6c9f07bf8800171de2cd3f02815cebe1f4d45f2d git.kernel.org: https://git.kernel.org/stable/c/259caa711b7688365676442e2fdb286b8aceaa80 git.kernel.org: https://git.kernel.org/stable/c/968550a439f64bd1a6c0d88efb92e4f082f84a26 git.kernel.org: https://git.kernel.org/stable/c/a9551f26287debe6d8aa6e8841974661065b975f git.kernel.org: https://git.kernel.org/stable/c/c82b797abe668d0b668601a93ba2c0b071a63574