CVE-2026-90248
CVE CVE-2026-90248EUVD EUVD-2026-81841Published 2026-09-17T16:07:50.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted proto on insert-race loss In tc_new_tfilter() the create branch sets tp_created = 1 before calling tcf_chain_tp_insert_unique(). When the caller loses the race (another request inserted a proto at the same chain/prio first), insert_unique() destroys the caller's own tp_new and returns the winner's proto with an extra reference. tp_created was never cleared, so the loser's errout path treated the winner's live proto as its own and called tcf_chain_tp_delete_empty() on it, silently unlinking an active classifier that the winning request already advertised via RTM_NEWTFILTER. Track the outcome of the insert step in a single tri-state variable so each errout path reacts correctly: - TP_NOT_CREATED: no proto created; pursue the old path. - TP_CREATED: proto inserted successfully; same code path as before. - TP_NOT_OWNED: New - lost the insert race; tp is another request's proto (chain ref already released by tp_new's destroy) Both errout reactions are single expressions derived from the state. This fix is motivated by the Sashiko's automated review of Patch (net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers) [1][2]. The review identified the silent-unlink behaviour of an adopted proto's teardown when a request loses the tcf_chain_tp_insert_unique() race. [1] https://sashiko.dev/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com [2] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.3-rc1; patch: 6.12.110; patch: 6.6.157; patch: 0; patch: 7.2.6; 8b64678e0af8f4d62a40149baedebe78503a5255 <219c87aeefdcc8c1caf28cc99e9b361ce7393d3a; 8b64678e0af8f4d62a40149baedebe78503a5255 <dc8b33b819cb02a75936940c120aa669ad89942d; patch: 5.15.221; 8b64678e0af8f4d62a40149baedebe78503a5255 <df02b6dc136af45e92ee4c86f4aa6c9a60790b1e; 8b64678e0af8f4d62a40149baedebe78503a5255 <bee2208276c8e0e40a249ffdcf6e5434a79a847c; patch: 6.1.188; 5.1; 8b64678e0af8f4d62a40149baedebe78503a5255 <bbe2fd6d77df630356185406a97317f6aa6a92cf; 8b64678e0af8f4d62a40149baedebe78503a5255 <a68e664ddf16ecae6d769d6a2eb356f8abab75c9; 8b64678e0af8f4d62a40149baedebe78503a5255 <d4e359b3608a0e184bbe8d61a5c3b50d0831c44a; patch: 6.18.52
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.