Linux Kernel Vulnerability in Network Scheduler by Linux Foundation
CVE-2026-98017

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98017?

A vulnerability exists in the Linux kernel's network scheduler where an improper handling of resource management during the initialization process can lead to unexpected behavior. Specifically, an RTM_NEWQDISC request could trigger clsact to bind an already populated shared ingress block. If there is an invalid TCA_RATE, the estimator setup will fail after initialization, and the resulting unwind process compromises resource management, potentially freeing a qdisc while still in use. This issue emphasizes the need for robust handling and destruction of resources in kernel-level code to maintain system integrity.

Affected Version(s)

Linux 51ab2994c387c80b45caf8b8067b3f3b97771d25 < 96a27a3e64e7c87abade03fb2ad04ed66992a89a

Linux 51ab2994c387c80b45caf8b8067b3f3b97771d25 < 6a1b49bb9fdf9e8e7aa38e8cd635c0cc4074447d

Linux 51ab2994c387c80b45caf8b8067b3f3b97771d25 < 20bf6fa34b345333971bd4464a322cce87b83f4e

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.