Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98380— net/sched: reject IDR error pointers when deleting actions

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已解决以下漏洞: net/sched: 在删除动作(actions)时,拒绝无效的 IDR 错误指针 在调用 并传入保存的动作索引之前,会释放其查找引用所持有的引用计数。在此期间,一个未加锁的分类器(classifier)可能会移除该动作,并保留相同的 IDR 槽位,同时将其标记为 。 仅检查查找结果是否为 。因此,它将这种保留状态视为一个正常的 对象,并解引用 字段。我们使用硬件执行断点来调度这种并发交错场景,而无需修改内核源代码。KASAN(内核地址 sanitizer)报告了以下解码后

AI Predicted 7.8 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98380

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/sched: reject IDR error pointers when deleting actions
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: reject IDR error pointers when deleting actions tcf_action_delete() drops the reference held by its lookup before calling tcf_idr_delete_index() with the saved action index. An unlocked classifier can remove that action and reserve the same IDR slot with ERR_PTR(-EBUSY) in between. tcf_idr_delete_index() only checks the lookup result for NULL. It therefore treats the reservation as a tc_action and dereferences tcfa_bindcnt. A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source. KASAN reported this decoded trace: BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010 Read of size 4 at addr 0000000000000010 by task poc/150 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002 RIP: tca_action_gd+0x5c0/0x1010: arch_atomic_read at arch/x86/include/asm/atomic.h:23 raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457 atomic_read at include/linux/atomic/atomic-instrumented.h:33 tcf_idr_delete_index at net/sched/act_api.c:766 tcf_action_delete at net/sched/act_api.c:1859 tcf_del_notify at net/sched/act_api.c:2014 tca_action_gd at net/sched/act_api.c:2064 R13: 0000000000000010 R15: fffffffffffffff0 Kernel panic - not syncing: Fatal exception R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces the address in R13. With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic. Treat error pointers as absent and return -ENOENT.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8 ~ 39b751a210bf61a374afa82749afc7a77a08bf1d -
Linux Linux 4.19 -

II. Public POCs for CVE-2026-98380

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98380

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98380 (8)

Same Patch Batch · Linux · 2026-10-09 · 10 CVEs total

CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices
CVE-2026-98381 veth: manage XDP program pointers during channel resize
CVE-2026-98378 bpf: Skip unsettled links in link iterator
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag()
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header

IV. Related Vulnerabilities

V. Comments for CVE-2026-98380

No comments yet


Leave a comment