CVE-2026-23436
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect from late creation of hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections.
The netdev may get unregistered in between the time we take the ref and the time we lock it. We may allocate the hierarchy after flush has already run, which would lead to a leak.
Take the instance lock in pre- already, this saves us from the race and removes the need for dedicated lock/unlock callbacks completely. After all, if there's any chance of write happening concurrently with the flush - we're back to leaking the hierarchy.
Leer descripción completaMostrar menos
We may take the lock for devices which don't support shapers but we're only dealing with SET operations here, not taking the lock would be optimizing for an error case.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23436",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "93954b40f6a4fc43226c01a15b02732f884500f1",
"lessThan": "719f6784f918f9e32f3ff3b197f900e852223f9d",
"versionType": "git"
},
{
"status": "affected",
"version": "93954b40f6a4fc43226c01a15b02732f884500f1",
"lessThan": "d22921727023e7852704965e935f4d1fc83a5ec9",
"versionType": "git"
},
{
"status": "affected",
"version": "93954b40f6a4fc43226c01a15b02732f884500f1",
"lessThan": "d75ec7e8ba1979a1eb0b9211d94d749cdce849c8",
"versionType": "git"
}
],
"programFiles": [
"Documentation/netlink/specs/net_shaper.yaml",
"net/shaper/shaper.c",
"net/shaper/shaper_nl_gen.c",
"net/shaper/shaper_nl_gen.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.20",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"Documentation/netlink/specs/net_shaper.yaml",
"net/shaper/shaper.c",
"net/shaper/shaper_nl_gen.c",
"net/shaper/shaper_nl_gen.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-04-03T16:16:25.257",
"references": [
{
"url": "https://git.kernel.org/stable/c/719f6784f918f9e32f3ff3b197f900e852223f9d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d22921727023e7852704965e935f4d1fc83a5ec9",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d75ec7e8ba1979a1eb0b9211d94d749cdce849c8",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: shaper: protect from late creation of hierarchy\n\nWe look up a netdev during prep of Netlink ops (pre- callbacks)\nand take a ref to it. Then later in the body of the callback\nwe take its lock or RCU which are the actual protections.\n\nThe netdev may get unregistered in between the time we take\nthe ref and the time we lock it. We may allocate the hierarchy\nafter flush has already run, which would lead to a leak.\n\nTake the instance lock in pre- already, this saves us from the race\nand removes the need for dedicated lock/unlock callbacks completely.\nAfter all, if there's any chance of write happening concurrently\nwith the flush - we're back to leaking the hierarchy.\n\nWe may take the lock for devices which don't support shapers but\nwe're only dealing with SET operations here, not taking the lock\nwould be optimizing for an error case."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnet: shaper: proteger de la creación tardía de la jerarquía\n\nBuscamos un netdev durante la preparación de las operaciones de Netlink (callbacks previos) y tomamos una referencia a él. Luego, más tarde, en el cuerpo del callback, tomamos su bloqueo o RCU, que son las protecciones reales.\n\nEl netdev puede ser dado de baja entre el momento en que tomamos la referencia y el momento en que lo bloqueamos. Podemos asignar la jerarquía después de que el vaciado ya se haya ejecutado, lo que llevaría a una fuga.\n\nTomar el bloqueo de instancia ya en pre-, esto nos salva de la condición de carrera y elimina por completo la necesidad de callbacks dedicados de bloqueo/desbloqueo. Después de todo, si hay alguna posibilidad de que una escritura ocurra concurrentemente con el vaciado, volvemos a la fuga de la jerarquía.\n\nPodemos tomar el bloqueo para dispositivos que no soportan shapers, pero aquí solo estamos tratando con operaciones SET; no tomar el bloqueo sería optimizar para un caso de error."
}
],
"lastModified": "2026-07-24T21:10:00.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2A94618-E3D4-4741-B60F-78501912CE89",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "6.13.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96D34333-38BE-4414-9E79-6EB764329581",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A3F9505-6B98-4269-8B81-127E55A1BF00"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58A9FEFF-C040-420D-8F0A-BFDAAA1DF258"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D2315C0-D46F-4F85-9754-F9E5E11374A6"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "512EE3A8-A590-4501-9A94-5D4B268D6138"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}