HIGHCVE-2026-23245Published Modified CNA Linux
CVE-2026-23245: net/sched: act_gate: snapshot parameters with RCU on replace
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Convert the parameters to an RCU-protected snapshot and swap updates under tcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits the entry list, preserve the existing schedule so the effective state is unchanged.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
0035d0d09d5ab3ed3e93d18cde2b562a6719eea2304d75529dc0f9be78786162ebab7424af4644df25.10.25358b162e318d0243ad2d7d92456c0873f2494c3516.1.1676.6.1306.12.786.18.186.19.862413a9c3cb183afb9bb6e94dd68caf4e4145f4c7.08b1251bbf0f10ac745ed74bad4d3b433caa1eeaedfc314d7c767e350f78a46a8f8b134f80e8ad432fc98fd8d214693be91253d9a88cdf8e5e143d124
Affected packages
- Linux / Linux< fc98fd8d214693be91253d9a88cdf8e5e143d124 (from a51c328df3106663879645680609eb49b3ff6444) · < 8b1251bbf0f10ac745ed74bad4d3b433caa1eeae (from a51c328df3106663879645680609eb49b3ff6444) · < dfc314d7c767e350f78a46a8f8b134f80e8ad432 (from a51c328df3106663879645680609eb49b3ff6444) · < 035d0d09d5ab3ed3e93d18cde2b562a6719eea23 (from a51c328df3106663879645680609eb49b3ff6444) · < 04d75529dc0f9be78786162ebab7424af4644df2 (from a51c328df3106663879645680609eb49b3ff6444) · < 58b162e318d0243ad2d7d92456c0873f2494c351 (from a51c328df3106663879645680609eb49b3ff6444)
- Linux / Linux5.8Fixed in 0, 5.10.253, 6.1.167, 6.6.130, 6.12.78, 6.18.18, 6.19.8, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H