HIGHCVE-2026-23437Published Modified CNA Linux
CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy
In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections. This is not proper, a conversion from a ref to a locked netdev must include a liveness check (a check if the netdev hasn't been unregistered already). Fix the read cases (those under RCU). Writes needs a separate change to protect from creating the hierarchy after flush has already run.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
00f9ea7141f365b4f27226898e62220fb98ef8dc6348758ba74e6a348299965b16a97cfb817545cc0581eee0890a8bde44f1fb78ad3e70502a897d5836.18.206.19.107.0
Affected packages
- Linux / Linux< 581eee0890a8bde44f1fb78ad3e70502a897d583 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb) · < 348758ba74e6a348299965b16a97cfb817545cc0 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb) · < 0f9ea7141f365b4f27226898e62220fb98ef8dc6 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb)
- Linux / Linux6.13Fixed in 0, 6.18.20, 6.19.10, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H