7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
Basic Information
ID
CVE-2026-23437
Source
Linux
Published
Apr 3, 2026 at 15:15
Modified
Apr 27, 2026 at 14:02
Affected Product
Vendor
Linux
Product
Linux
Version
4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Affected Versions
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 6.13
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 6.13