← All Advisories

CVE-2026-23413

Status: UPDATED  |  Advisory ID: CVE-2026-23413

Key Details

CVECVE-2026-23413
CVSSCVSS 7.8 (High).
Affected productsLinux Linux Kernel
Classified asCWE-416 (Use After Free)

What to Know

In the Linux kernel, the following vulnerability has been resolved:

clsact: Fix use-after-free in init/destroy rollback asymmetry

Fix a use-after-free in the clsact qdisc upon init/destroy rollback asymmetry.

The latter is achieved by first fully initializing a clsact instance, and

then in a second step having a replacement failure for the new clsact qdisc

instance. clsact_init() initializes ingress first and then takes care of the

egress part. This can fail midway, for example, via tcf_block_get_ext(). Upon

failure, the kernel will trigger the clsact_destroy() callback.

Commit 1cb6f0bae504 ("bpf: Fix too early release of tcx_entry") details the

way how the transition is happening. If tcf_block_get_ext on the q->ingress_block

ends up failing, we took the tcx_miniq_inc reference count on the ingress

side, but not yet on the egress side. clsact_destroy() tests whether the

{ingress,egress}_entry was non-NULL. However, even in midway failure on the

replacement, both are in fact non-NULL with a valid egress_entry from the

previous clsact instance.

What we really need to test for is whether the qdisc instance-specific ingress

or egress side previously got initialized. This adds a small helper for checking

the miniq initialization called mini_qdisc_pair_inited, and utilizes that upon

clsact_destroy() in order to fix the use-after-free scenario. Convert the

ingress_destroy() side as well so both are consistent to each other.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-23413