Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: reject IDR error pointers when deleting actions

tcf_action_delete() drops the reference held by its lookup before calling
tcf_idr_delete_index() with the saved action index. An unlocked
classifier can remove that action and reserve the same IDR slot with
ERR_PTR(-EBUSY) in between.

tcf_idr_delete_index() only checks the lookup result for NULL. It
therefore treats the reservation as a tc_action and dereferences
tcfa_bindcnt. A hardware execution breakpoint was used to schedule the
interleaving without changing the kernel source. KASAN reported this
decoded trace:

BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010
Read of size 4 at addr 0000000000000010 by task poc/150
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002
RIP: tca_action_gd+0x5c0/0x1010:
arch_atomic_read at arch/x86/include/asm/atomic.h:23
raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457
atomic_read at include/linux/atomic/atomic-instrumented.h:33
tcf_idr_delete_index at net/sched/act_api.c:766
tcf_action_delete at net/sched/act_api.c:1859
tcf_del_notify at net/sched/act_api.c:2014
tca_action_gd at net/sched/act_api.c:2064
R13: 0000000000000010 R15: fffffffffffffff0
Kernel panic - not syncing: Fatal exception

R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces
the address in R13. With the guard applied, the same reproducer returned
-ENOENT without a KASAN report or panic. Treat error pointers as absent
and return -ENOENT.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Panic (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel net/sched subsystem, a flaw was discovered in tcf_action_delete() and tcf_idr_delete_index() where error pointers returned as ERR_PTR(-EBUSY) are incorrectly treated as valid action structures during deletion, resulting in a null pointer dereference of tcfa_bindcnt and a general protection fault that triggers a kernel panic. This flaw reflects a memory safety defect stemming from improper error pointer handling and causes a loss of service as the system reboots.

Affected Systems

The affected products are the Linux kernel. No specific kernel release is enumerated in the CVE data, so any kernel versions containing the vulnerable tcf_idr_delete_index() implementation may be impacted until the fix commit is incorporated.

Risk and Exploitability

The CVSS score is not disclosed and EPSS data is unavailable, but the kernel crash demonstrates a high impact. Based on the description, the likely attack vector is local privilege or control over traffic‑control commands that can trigger the deletion sequence. An attacker who can invoke tc actions that interleave deletions and reservations may cause a denial of service by forcing a kernel panic. The vulnerability is not listed in CISA's KEV catalog, and no remote exploitation path is documented, but local exploitation remains feasible and poses a substantial risk.

Generated by OpenCVE AI on October 9, 2026 at 09:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit guarding against error pointers in tcf_idr_delete_index() (e.g., commit 259caa711b7688365676442e2fdb286b8aceaa80).
  • Reboot or reload the kernel after applying the update to ensure the patch takes effect.
  • If a kernel upgrade is not immediately feasible, reduce exposure by limiting the use of traffic‑control actions that can trigger deletions, or remove the offending users or services that can manipulate tc actions.

Generated by OpenCVE AI on October 9, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: reject IDR error pointers when deleting actions tcf_action_delete() drops the reference held by its lookup before calling tcf_idr_delete_index() with the saved action index. An unlocked classifier can remove that action and reserve the same IDR slot with ERR_PTR(-EBUSY) in between. tcf_idr_delete_index() only checks the lookup result for NULL. It therefore treats the reservation as a tc_action and dereferences tcfa_bindcnt. A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source. KASAN reported this decoded trace: BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010 Read of size 4 at addr 0000000000000010 by task poc/150 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002 RIP: tca_action_gd+0x5c0/0x1010: arch_atomic_read at arch/x86/include/asm/atomic.h:23 raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457 atomic_read at include/linux/atomic/atomic-instrumented.h:33 tcf_idr_delete_index at net/sched/act_api.c:766 tcf_action_delete at net/sched/act_api.c:1859 tcf_del_notify at net/sched/act_api.c:2014 tca_action_gd at net/sched/act_api.c:2064 R13: 0000000000000010 R15: fffffffffffffff0 Kernel panic - not syncing: Fatal exception R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces the address in R13. With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic. Treat error pointers as absent and return -ENOENT.
Title net/sched: reject IDR error pointers when deleting actions
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:20.218Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98380

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.400

Modified: 2026-10-09T08:16:56.400

Link: CVE-2026-98380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:45:04Z

Weaknesses