Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_api: fix teardown of an adopted proto on insert-race loss

In tc_new_tfilter() the create branch sets tp_created = 1 before calling
tcf_chain_tp_insert_unique(). When the caller loses the race (another
request inserted a proto at the same chain/prio first), insert_unique()
destroys the caller's own tp_new and returns the winner's proto with an
extra reference. tp_created was never cleared, so the loser's errout
path treated the winner's live proto as its own and called
tcf_chain_tp_delete_empty() on it, silently unlinking an active
classifier that the winning request already advertised via
RTM_NEWTFILTER.

Track the outcome of the insert step in a single tri-state variable so
each errout path reacts correctly:

- TP_NOT_CREATED: no proto created; pursue the old path.
- TP_CREATED: proto inserted successfully; same code path as before.
- TP_NOT_OWNED: New - lost the insert race; tp is another request's proto
(chain ref already released by tp_new's destroy)

Both errout reactions are single expressions derived from the state.

This fix is motivated by the Sashiko's automated review of Patch
(net/sched: cls_api: Always acquire rtnl_lock when destroying locked
classifiers) [1][2]. The review identified the silent-unlink behaviour of
an adopted proto's teardown when a request loses the
tcf_chain_tp_insert_unique() race.

[1] https://sashiko.dev/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
[2] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via silent deletion of an active classifier
Action: Apply Patch Immediately
AI Analysis

Impact

A race condition in the Linux kernel’s traffic‑control (net/sched) cls_api module allows two concurrent tc commands to interfere with each other. When an insert operation loses a race, the error path mistakenly interprets the already‑installed classifier as its own and unlinks it from the active filter chain, silently removing that rule. The consequence is a sudden loss of traffic shaping or filtering rules that can disrupt services relying on exact packet classification, effectively causing a denial of service.

Affected Systems

The flaw affects all publicly released Linux kernel versions that include the cls_api module; no particular version numbers are listed. Administrators should verify that the running kernel is based on a release that contains the upstream patch, which can be confirmed by searching kernel release notes or changelogs for the fix to the cls_api race condition.

Risk and Exploitability

The vulnerability’s exploitation window requires privileged access, typically root or a process with CAP_NET_ADMIN, to invoke tc commands that trigger the insert race. The EPSS score is reported as less than 1 %, indicating a very low probability of real‑world exploitation at this time, and the flaw is not listed in the CISA KEV catalog. Despite the low likelihood, any successful race would silently break traffic control configuration, and the impact is significant in environments where precise packet filtering or quality‑of‑service enforcement is critical.

Generated by OpenCVE AI on September 19, 2026 at 15:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a released version that incorporates the cls_api race‑condition patch
  • Limit use of traffic control commands by granting CAP_NET_ADMIN only to trusted users or services that truly require it
  • Enable audit logging for all tc operations to detect unexpected classifier deletions or unauthorized attempts to modify traffic rules

Generated by OpenCVE AI on September 19, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted proto on insert-race loss In tc_new_tfilter() the create branch sets tp_created = 1 before calling tcf_chain_tp_insert_unique(). When the caller loses the race (another request inserted a proto at the same chain/prio first), insert_unique() destroys the caller's own tp_new and returns the winner's proto with an extra reference. tp_created was never cleared, so the loser's errout path treated the winner's live proto as its own and called tcf_chain_tp_delete_empty() on it, silently unlinking an active classifier that the winning request already advertised via RTM_NEWTFILTER. Track the outcome of the insert step in a single tri-state variable so each errout path reacts correctly: - TP_NOT_CREATED: no proto created; pursue the old path. - TP_CREATED: proto inserted successfully; same code path as before. - TP_NOT_OWNED: New - lost the insert race; tp is another request's proto (chain ref already released by tp_new's destroy) Both errout reactions are single expressions derived from the state. This fix is motivated by the Sashiko's automated review of Patch (net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers) [1][2]. The review identified the silent-unlink behaviour of an adopted proto's teardown when a request loses the tcf_chain_tp_insert_unique() race. [1] https://sashiko.dev/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com [2] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
Title net/sched: cls_api: fix teardown of an adopted proto on insert-race loss
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:50.104Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90248

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:20.947

Modified: 2026-09-17T17:17:20.947

Link: CVE-2026-90248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')