CVE-2026-72338
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
There is a TOCTOU race condition in flower lockless approach between sizing a flow_rule buffer and filling it. zdi-disclosures@trendmicro.com reports: The cls_flower classifier operates with TCF_PROTO_OPS_DOIT_UNLOCKED (fl_change runs without RTNL), while RTM_NEWACTION holds RTNL, so the independent locking domains make the race reachable in practice.
Leer descripción completaMostrar menos
KASAN confirms: BUG: KASAN: slab-out-of-bounds in tcf_pedit_offload_act_setup+0x81b/0x930 Write of size 4 at addr ffff888001f27520 by task poc-toctou/312 The buggy address is located 0 bytes to the right of allocated 288-byte region [ffff888001f27400, ffff888001f27520) (cache kmalloc-512)
Note: The result is a heap OOB write attacker-controlled content into the adjacent slab object (requires CAP_NET_ADMIN).
The fix introduces reading tcfp_nkeys under act->tcfa_lock in all places using a new tcf_pedit_nkeys_locked() which replaces the old tcf_pedit_nkeys(). Additionally we close the remaining TOCTOU window between the sizing read and the fill reads by more careful accounting. Rather than silently truncating the key count, which leads to incorrect action semantics offloaded to hardware and secondary OOB writes if the remaining capacity is zero or consumed by prior actions, we enforce remaining capacity checks and return -ENOSPC if the required space exceeds the remaining capacity.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1005Data from Local Systemcollection75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact70 %
Acceso local (AV:L, PR:L) permite escalar privilegios mediante carrera TOCTOU en heap OOB write; lectura de memoria adyacente y corrupción de datos en objetos slab contiguo.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0d8532a5e972a5351cf4ee4a435e0d65cbba8f23
- https://git.kernel.org/stable/c/27488e1a7f19757e6146edca9458ed4ffc545557
- https://git.kernel.org/stable/c/6f9b23eb92a894ae1118893996943990ee0b860e
- https://git.kernel.org/stable/c/8b519cbcabe836a441369fbec1a8a6518a709251
- https://git.kernel.org/stable/c/8e49cd891bda447c68122d672510a604a8bb6b24
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72338",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "71d0ed7079dffbc5cd0941d77d9b84e04109c9bb",
"lessThan": "0d8532a5e972a5351cf4ee4a435e0d65cbba8f23",
"versionType": "git"
},
{
"status": "affected",
"version": "71d0ed7079dffbc5cd0941d77d9b84e04109c9bb",
"lessThan": "27488e1a7f19757e6146edca9458ed4ffc545557",
"versionType": "git"
},
{
"status": "affected",
"version": "71d0ed7079dffbc5cd0941d77d9b84e04109c9bb",
"lessThan": "6f9b23eb92a894ae1118893996943990ee0b860e",
"versionType": "git"
},
{
"status": "affected",
"version": "71d0ed7079dffbc5cd0941d77d9b84e04109c9bb",
"lessThan": "8e49cd891bda447c68122d672510a604a8bb6b24",
"versionType": "git"
},
{
"status": "affected",
"version": "71d0ed7079dffbc5cd0941d77d9b84e04109c9bb",
"lessThan": "8b519cbcabe836a441369fbec1a8a6518a709251",
"versionType": "git"
}
],
"programFiles": [
"include/net/tc_act/tc_pedit.h",
"net/sched/act_api.c",
"net/sched/act_pedit.c",
"net/sched/cls_api.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/net/tc_act/tc_pedit.h",
"net/sched/act_api.c",
"net/sched/act_pedit.c",
"net/sched/cls_api.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:07.043",
"references": [
{
"url": "https://git.kernel.org/stable/c/0d8532a5e972a5351cf4ee4a435e0d65cbba8f23",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/27488e1a7f19757e6146edca9458ed4ffc545557",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6f9b23eb92a894ae1118893996943990ee0b860e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8b519cbcabe836a441369fbec1a8a6518a709251",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8e49cd891bda447c68122d672510a604a8bb6b24",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_pedit: fix TOCTOU heap OOB write in tc offload\n\nThere is a TOCTOU race condition in flower lockless approach between sizing\na flow_rule buffer and filling it.\nzdi-disclosures@trendmicro.com reports:\nThe cls_flower classifier operates with TCF_PROTO_OPS_DOIT_UNLOCKED\n(fl_change runs without RTNL), while RTM_NEWACTION holds RTNL, so the\nindependent locking domains make the race reachable in practice. KASAN\nconfirms:\n BUG: KASAN: slab-out-of-bounds in tcf_pedit_offload_act_setup+0x81b/0x930\n Write of size 4 at addr ffff888001f27520 by task poc-toctou/312\n The buggy address is located 0 bytes to the right of\n allocated 288-byte region [ffff888001f27400, ffff888001f27520)\n (cache kmalloc-512)\n\nNote: The result is a heap OOB write attacker-controlled content into the\nadjacent slab object (requires CAP_NET_ADMIN).\n\nThe fix introduces reading tcfp_nkeys under act->tcfa_lock in all places\nusing a new tcf_pedit_nkeys_locked() which replaces the old tcf_pedit_nkeys().\nAdditionally we close the remaining TOCTOU window between the sizing read and\nthe fill reads by more careful accounting.\nRather than silently truncating the key count, which leads to incorrect\naction semantics offloaded to hardware and secondary OOB writes if\nthe remaining capacity is zero or consumed by prior actions, we enforce\nremaining capacity checks and return -ENOSPC if the required space exceeds\nthe remaining capacity."
}
],
"lastModified": "2026-08-17T06:18:37.493",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}