CVE-2026-68138
In the Linux kernel, the following vulnerability has been resolved:
net/sched: serialize qdisc_rtab_list against concurrent get/put
qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no lock. This was only safe because every caller historically held the RTNL mutex, which serialized all rate-table lookups, inserts and frees.
That invariant no longer holds. cls_flower sets TCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false for it and sets TCA_ACT_FLAGS_NO_RTNL.
Leer descripción completaMostrar menos
That flag propagates through tcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() -> tcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the RTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each adding a flower filter with a police action carrying the same rate, then race on qdisc_rtab_list and on the non-atomic refcnt, leading to a use-after-free / double-free of the kmalloc-2k struct qdisc_rate_table. qdisc_rtab_list is a single global (not per-netns), so the corrupted object is shared system-wide.
Protect qdisc_rtab_list and the refcount with a dedicated spinlock. The (sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before taking the lock; if a concurrent inserter added an identical table in the meantime the freshly allocated one is freed under the lock, so no duplicate is leaked. qdisc_put_rtab() now decrements the refcount and unlinks under the same lock.
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160 qdisc_put_rtab+0x12f/0x160 tcf_police_init+0xda9/0x1590 tcf_action_init_1+0x460/0x6b0 tcf_action_init+0x439/0xa40 tcf_exts_validate_ex+0x42d/0x550 fl_change+0xddd/0x7da0 tc_new_tfilter+0xaa7/0x2420 rtnetlink_rcv_msg+0x95e/0xe90 which belongs to the cache kmalloc-2k of size 2048
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact60 %
Vulnerabilidad local (AV:L/PR:L) sin interacción del usuario que causa use-after-free/double-free en kernel, permitiendo DoS o corrupción de memoria con privilegios elevados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1b050d09dd1a0ddae83bf012cf4956b7a960235f
- https://git.kernel.org/stable/c/4131dd0b6f67acddd616ed7c244e1d3eedd46e7b
- https://git.kernel.org/stable/c/6e0241f6cbb149d926ee8efee2c734fea71452cf
- https://git.kernel.org/stable/c/8ddc2eb0d2da9c83f54f1e5720525b461b8480c4
- https://git.kernel.org/stable/c/d981098b76756ed71666a27518eeb69883657c43
- https://git.kernel.org/stable/c/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047
- https://git.kernel.org/stable/c/f93c89392bd3b180b5b7abc6fdae8e3dd667a313
- https://git.kernel.org/stable/c/fb29e1b41052488ee3f2d115d4a870497ebd7f7d
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68138",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "1b050d09dd1a0ddae83bf012cf4956b7a960235f",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "6e0241f6cbb149d926ee8efee2c734fea71452cf",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "f93c89392bd3b180b5b7abc6fdae8e3dd667a313",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "4131dd0b6f67acddd616ed7c244e1d3eedd46e7b",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "d981098b76756ed71666a27518eeb69883657c43",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "8ddc2eb0d2da9c83f54f1e5720525b461b8480c4",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "fb29e1b41052488ee3f2d115d4a870497ebd7f7d",
"versionType": "git"
},
{
"status": "affected",
"version": "470502de5bdb1ed0def643a4458593a40b8f6b66",
"lessThan": "f43ee0c0730d6191629b5ee1ceae27b1ebfdc047",
"versionType": "git"
}
],
"programFiles": [
"net/sched/sch_api.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/sched/sch_api.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:19:59.410",
"references": [
{
"url": "https://git.kernel.org/stable/c/1b050d09dd1a0ddae83bf012cf4956b7a960235f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4131dd0b6f67acddd616ed7c244e1d3eedd46e7b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6e0241f6cbb149d926ee8efee2c734fea71452cf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8ddc2eb0d2da9c83f54f1e5720525b461b8480c4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d981098b76756ed71666a27518eeb69883657c43",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f93c89392bd3b180b5b7abc6fdae8e3dd667a313",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fb29e1b41052488ee3f2d115d4a870497ebd7f7d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: serialize qdisc_rtab_list against concurrent get/put\n\nqdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly\nlinked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no\nlock. This was only safe because every caller historically held the RTNL\nmutex, which serialized all rate-table lookups, inserts and frees.\n\nThat invariant no longer holds. cls_flower sets\nTCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false\nfor it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through\ntcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() ->\ntcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the\nRTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each\nadding a flower filter with a police action carrying the same rate, then\nrace on qdisc_rtab_list and on the non-atomic refcnt, leading to a\nuse-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.\nqdisc_rtab_list is a single global (not per-netns), so the corrupted\nobject is shared system-wide.\n\n BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160\n qdisc_put_rtab+0x12f/0x160\n tcf_police_init+0xda9/0x1590\n tcf_action_init_1+0x460/0x6b0\n tcf_action_init+0x439/0xa40\n tcf_exts_validate_ex+0x42d/0x550\n fl_change+0xddd/0x7da0\n tc_new_tfilter+0xaa7/0x2420\n rtnetlink_rcv_msg+0x95e/0xe90\n which belongs to the cache kmalloc-2k of size 2048\n\nProtect qdisc_rtab_list and the refcount with a dedicated spinlock. The\n(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before\ntaking the lock; if a concurrent inserter added an identical table in the\nmeantime the freshly allocated one is freed under the lock, so no\nduplicate is leaked. qdisc_put_rtab() now decrements the refcount and\nunlinks under the same lock."
}
],
"lastModified": "2026-08-23T13:16:33.780",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}