HarborGuard / CVE
Back to search
HIGHCVE-2026-23437Published Modified CNA Linux

CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy

In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections. This is not proper, a conversion from a ref to a locked netdev must include a liveness check (a check if the netdev hasn't been unregistered already). Fix the read cases (those under RCU). Writes needs a separate change to protect from creating the hierarchy after flush has already run.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
0
Affected Products
2

Fix available

00f9ea7141f365b4f27226898e62220fb98ef8dc6348758ba74e6a348299965b16a97cfb817545cc0581eee0890a8bde44f1fb78ad3e70502a897d5836.18.206.19.107.0
Affected packages
  • Linux / Linux
    < 581eee0890a8bde44f1fb78ad3e70502a897d583 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb) · < 348758ba74e6a348299965b16a97cfb817545cc0 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb) · < 0f9ea7141f365b4f27226898e62220fb98ef8dc6 (from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb)
  • Linux / Linux
    6.13
    Fixed in 0, 6.18.20, 6.19.10, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H