CVE 7.8 HIGH

net: shaper: protect late read accesses to the hierarchy_CVE-2026-23437

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

net: shaper: protect late read accesses to the hierarchy

We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.

This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.

Basic Information

ID CVE-2026-23437
Source Linux
Published Apr 3, 2026 at 15:15
Modified Apr 27, 2026 at 14:02

Affected Product

Vendor Linux
Product Linux
Version 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Affected Versions Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb
Linux Linux 6.13

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.