« Volver al listado

CVE-2026-98104

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted

gen_new_kid() falls back to returning max (htid | 0xFFF) when both idr_alloc_u32() ranges are full, instead of reporting an error. u32_change() trusts that value and inserts a new knode with a handle that is already live in the hash table, breaking handle uniqueness within the table's node ID space.

The handle was never reserved in ht->handle_idr, so every later error path that does idr_remove(&ht->handle_idr, handle) removes the reservation of a different, live knode, which is then reused — one failed add compounds into further duplicates.

Leer descripción completaMostrar menos

The 4095 limit is per (table, bucket) — ht->handle_idr is per hash table and the range is derived from htid (bucketid), so a table with divisor 256 can legitimately hold 256*4095 knodes.

The sibling helper gen_new_htid() has the same silent in-band failure: it returns 0 when the tp_c handle pool (1..0x7FF) is full, and u32_init() publishes the root hash table with handle 0 without checking. Two root tables with handle 0 alias in u32_lookup_ht(), allowing cross-tcf_proto knode add/lookup/delete. Add the same exhaustion check that the divisor path already has.

Return an error so u32_change() fails with ENOSPC/ENOMEM when the node ID space is exhausted, and so u32_init() fails with -ENOMEM when the hash table ID space is exhausted. The extack message distinguishes pool exhaustion (-ENOSPC) from a transient allocation failure (-ENOMEM).

Detalles técnicos trazas, registros y código del informe original
Conditions to recreate the bug:
- CONFIG_NET_SCHED=y, CONFIG_CLS_U32=y (or =m with module loaded)
- Create a clsact qdisc on a device, then add 4095 u32 filters with
  auto-generated handles to fill the node ID space for the root hash
  table (single bucket). The 4096th auto-handle filter add triggers
  the duplicate handle (fh 800::fff reused). Reachable at Level 2
  (unshare -Urn, namespace-local CAP_NET_ADMIN).
- For gen_new_htid: create 2047 u32 proto entries on the same block
  to fill the tp_c handle pool, then create one more. The root table
  gets handle 0 and aliases with other handle-0 root tables.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98104",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7801db8aec957fa6610efe0ee26a6c8bc0f1d73b",
              "lessThan": "f4ee13ed7f7b22dcd8287fcf477ae37bd84567da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7801db8aec957fa6610efe0ee26a6c8bc0f1d73b",
              "lessThan": "84223baf21bc9b008444ae9bc38d5fb91fe00b9d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7801db8aec957fa6610efe0ee26a6c8bc0f1d73b",
              "lessThan": "6890e28840bae4f6805e8de981c4ec8e12a4e064",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7801db8aec957fa6610efe0ee26a6c8bc0f1d73b",
              "lessThan": "feab9261b537df4ebb8350e4779bc185373059fd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7801db8aec957fa6610efe0ee26a6c8bc0f1d73b",
              "lessThan": "f594f04268d01c5fdc975f3f51fc219ea2159ac6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7801db8aec957fa6610efe0ee26a6c8bc0f1d73b",
              "lessThan": "d7e7e98d23f42a92d9ab7e36302bd96bd9b33b5f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sched/cls_u32.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sched/cls_u32.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:40.793",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6890e28840bae4f6805e8de981c4ec8e12a4e064",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84223baf21bc9b008444ae9bc38d5fb91fe00b9d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7e7e98d23f42a92d9ab7e36302bd96bd9b33b5f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f4ee13ed7f7b22dcd8287fcf477ae37bd84567da",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f594f04268d01c5fdc975f3f51fc219ea2159ac6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/feab9261b537df4ebb8350e4779bc185373059fd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_u32: fix duplicate handle when node ID pool is exhausted\n\ngen_new_kid() falls back to returning max (htid | 0xFFF) when both\nidr_alloc_u32() ranges are full, instead of reporting an error.\nu32_change() trusts that value and inserts a new knode with a handle\nthat is already live in the hash table, breaking handle uniqueness\nwithin the table's node ID space.\n\nThe handle was never reserved in ht->handle_idr, so every later error\npath that does idr_remove(&ht->handle_idr, handle) removes the\nreservation of a different, live knode, which is then reused — one\nfailed add compounds into further duplicates.\n\nThe 4095 limit is per (table, bucket) — ht->handle_idr is per hash\ntable and the range is derived from htid (bucketid), so a table with\ndivisor 256 can legitimately hold 256*4095 knodes.\n\nThe sibling helper gen_new_htid() has the same silent in-band failure:\nit returns 0 when the tp_c handle pool (1..0x7FF) is full, and\nu32_init() publishes the root hash table with handle 0 without\nchecking.  Two root tables with handle 0 alias in u32_lookup_ht(),\nallowing cross-tcf_proto knode add/lookup/delete.  Add the same\nexhaustion check that the divisor path already has.\n\nReturn an error so u32_change() fails with ENOSPC/ENOMEM when the\nnode ID space is exhausted, and so u32_init() fails with -ENOMEM\nwhen the hash table ID space is exhausted.  The extack message\ndistinguishes pool exhaustion (-ENOSPC) from a transient allocation\nfailure (-ENOMEM).\n\nConditions to recreate the bug:\n- CONFIG_NET_SCHED=y, CONFIG_CLS_U32=y (or =m with module loaded)\n- Create a clsact qdisc on a device, then add 4095 u32 filters with\n  auto-generated handles to fill the node ID space for the root hash\n  table (single bucket). The 4096th auto-handle filter add triggers\n  the duplicate handle (fh 800::fff reused). Reachable at Level 2\n  (unshare -Urn, namespace-local CAP_NET_ADMIN).\n- For gen_new_htid: create 2047 u32 proto entries on the same block\n  to fill the tp_c handle pool, then create one more. The root table\n  gets handle 0 and aliases with other handle-0 root tables."
    }
  ],
  "lastModified": "2026-10-03T11:18:32.590",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}