CVE-2026-98380
Received Received - Intake

Null pointer dereference in Linux kernel traffic control

Vulnerability report for CVE-2026-98380, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: reject IDR error pointers when deleting actions tcf_action_delete() drops the reference held by its lookup before calling tcf_idr_delete_index() with the saved action index. An unlocked classifier can remove that action and reserve the same IDR slot with ERR_PTR(-EBUSY) in between. tcf_idr_delete_index() only checks the lookup result for NULL. It therefore treats the reservation as a tc_action and dereferences tcfa_bindcnt. A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source. KASAN reported this decoded trace: BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010 Read of size 4 at addr 0000000000000010 by task poc/150 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002 RIP: tca_action_gd+0x5c0/0x1010: arch_atomic_read at arch/x86/include/asm/atomic.h:23 raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457 atomic_read at include/linux/atomic/atomic-instrumented.h:33 tcf_idr_delete_index at net/sched/act_api.c:766 tcf_action_delete at net/sched/act_api.c:1859 tcf_del_notify at net/sched/act_api.c:2014 tca_action_gd at net/sched/act_api.c:2064 R13: 0000000000000010 R15: fffffffffffffff0 Kernel panic - not syncing: Fatal exception R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces the address in R13. With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic. Treat error pointers as absent and return -ENOENT.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux Linux 4.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the traffic control action deletion process. When deleting actions, the system fails to properly handle error pointers, leading to a null-pointer dereference. This occurs because an unlocked classifier can remove an action and reserve the same IDR slot with an error pointer, which is then incorrectly treated as a valid action, causing a kernel panic.

Detection Guidance

This vulnerability is specific to the Linux kernel's traffic control subsystem and requires kernel-level access to detect. Monitor kernel logs for KASAN reports or general protection faults related to tcf_action_gd or tcf_idr_delete_index. Check for crashes in kernel threads handling network traffic.

Impact Analysis

This vulnerability can cause system crashes due to kernel panics, leading to denial of service. Attackers could exploit it to trigger crashes by manipulating traffic control actions, potentially disrupting network services or causing system instability.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If patching is not immediately possible, consider disabling traffic control actions (tc) on affected systems until an update is applied. Monitor vendor advisories for kernel updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98380. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart