Impact
In the Linux kernel net/sched subsystem, a flaw was discovered in tcf_action_delete() and tcf_idr_delete_index() where error pointers returned as ERR_PTR(-EBUSY) are incorrectly treated as valid action structures during deletion, resulting in a null pointer dereference of tcfa_bindcnt and a general protection fault that triggers a kernel panic. This flaw reflects a memory safety defect stemming from improper error pointer handling and causes a loss of service as the system reboots.
Affected Systems
The affected products are the Linux kernel. No specific kernel release is enumerated in the CVE data, so any kernel versions containing the vulnerable tcf_idr_delete_index() implementation may be impacted until the fix commit is incorporated.
Risk and Exploitability
The CVSS score is not disclosed and EPSS data is unavailable, but the kernel crash demonstrates a high impact. Based on the description, the likely attack vector is local privilege or control over traffic‑control commands that can trigger the deletion sequence. An attacker who can invoke tc actions that interleave deletions and reservations may cause a denial of service by forcing a kernel panic. The vulnerability is not listed in CISA's KEV catalog, and no remote exploitation path is documented, but local exploitation remains feasible and poses a substantial risk.
OpenCVE Enrichment