Linux Kernel Vulnerability in Networking Scheduler by Various Affected Vendors
CVE-2026-98380
What is CVE-2026-98380?
In the Linux kernel, a vulnerability exists within the networking scheduler related to the handling of action deletion. The function tcf_action_delete() removes a reference but may inadvertently allow a competing process to reserve the same IDR index, leading to a null pointer dereference during the deletion process. This situation can cause a kernel panic, as the system attempts to dereference an invalid action reference. The issue has been addressed by ensuring that error pointers are treated as absent, preventing further complications and improving system stability.
Affected Version(s)
Linux 0190c1d452a91c38a3462abdd81752be1b9006a8 < 39b751a210bf61a374afa82749afc7a77a08bf1d
Linux 0190c1d452a91c38a3462abdd81752be1b9006a8
Linux 0190c1d452a91c38a3462abdd81752be1b9006a8 < 6bf076258aac4e0af69ef317656c31ce6444d647