CVE-2026-98017

HIGHCVSS 7.8/10

Last modified

CVE-2026-98017 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing after failed creation An RTM_NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini_Qdisc to lockless readers. If the same request has an invalid TCA_RATE, estimator setup fails after ->init(); the unwind removes the pointer but synchronously frees its containing qdisc while tc_run() may still hold it. Retire failed qdiscs through the same RCU helper as normal destruction. Inline the synchronous free into the callback now that no direct callers remain..

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing after failed creation An RTM_NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini_Qdisc to lockless readers. If the same request has an invalid TCA_RATE, estimator setup fails after ->init(); the unwind removes the pointer but synchronously frees its containing qdisc while tc_run() may still hold it. Retire failed qdiscs through the same RCU helper as normal destruction. Inline the synchronous free into the callback now that no direct callers remain.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 51ab2994c387c80b45caf8b8067b3f3b97771d25, < 20bf6fa34b345333971bd4464a322cce87b83f4e; >= 51ab2994c387c80b45caf8b8067b3f3b97771d25, < 156a3bab69744e9225bb9eff8c5cc53da18d5a2e; >= 51ab2994c387c80b45caf8b8067b3f3b97771d25, < 5bfe927c5b4b290fad529186218c728589b4b101; >= 51ab2994c387c80b45caf8b8067b3f3b97771d25, < e6662f2100f8d33b0f4d0047c219efd6bba186ea
LinuxLinux4.16

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-98017?
In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing after failed creation An RTM_NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini_Qdisc to lockless readers. If the same request has an invalid TCA_RATE, estimator setup fails after ->init(); the unwind removes the pointer but synchronously frees its containing qdisc while tc_run() may still hold it. Retire failed qdiscs through the same RCU helper as normal destruction. Inline the synchronous free into the callback now that no direct callers remain.
How severe is CVE-2026-98017?
CVE-2026-98017 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-98017?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-98017?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST