Linux Kernel Vulnerability in Network Scheduler by Linux Foundation
CVE-2026-98017
What is CVE-2026-98017?
A vulnerability exists in the Linux kernel's network scheduler where an improper handling of resource management during the initialization process can lead to unexpected behavior. Specifically, an RTM_NEWQDISC request could trigger clsact to bind an already populated shared ingress block. If there is an invalid TCA_RATE, the estimator setup will fail after initialization, and the resulting unwind process compromises resource management, potentially freeing a qdisc while still in use. This issue emphasizes the need for robust handling and destruction of resources in kernel-level code to maintain system integrity.
Affected Version(s)
Linux 51ab2994c387c80b45caf8b8067b3f3b97771d25 < 96a27a3e64e7c87abade03fb2ad04ed66992a89a
Linux 51ab2994c387c80b45caf8b8067b3f3b97771d25 < 6a1b49bb9fdf9e8e7aa38e8cd635c0cc4074447d
Linux 51ab2994c387c80b45caf8b8067b3f3b97771d25 < 20bf6fa34b345333971bd4464a322cce87b83f4e