{"id":"CVE-2026-98017","published":"2026-09-25T11:17:30.147","lastModified":"2026-09-25T15:18:03.697","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: defer qdisc freeing after failed creation\n\nAn RTM_NEWQDISC request can make clsact bind a populated shared ingress\nblock during ->init(), publishing an embedded mini_Qdisc to lockless\nreaders.  If the same request has an invalid TCA_RATE, estimator setup\nfails after ->init(); the unwind removes the pointer but synchronously\nfrees its containing qdisc while tc_run() may still hold it.\n\nRetire failed qdiscs through the same RCU helper as normal destruction.\nInline the synchronous free into the callback now that no direct callers\nremain.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/156a3bab69744e9225bb9eff8c5cc53da18d5a2e","tags":[]},{"url":"https://git.kernel.org/stable/c/20bf6fa34b345333971bd4464a322cce87b83f4e","tags":[]},{"url":"https://git.kernel.org/stable/c/5bfe927c5b4b290fad529186218c728589b4b101","tags":[]},{"url":"https://git.kernel.org/stable/c/e6662f2100f8d33b0f4d0047c219efd6bba186ea","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}