HIGH Public PoC Introduced in 5.1
net/sched QdiscRtab UAF
CVE-2026-68138
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no lock. This was only safe because every caller historically held the RTNL mutex, which serialized all rate-table lookups, inserts and frees. That invariant no longer holds. cls_flower sets TCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false for it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through tcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() -> tcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the RTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each adding a flower filter with a police action carrying the same rate, then race on qdisc_rtab_list and on the non-atomic refcnt, leading to a use-after-free / double-free of the kmalloc-2k struct qdisc_rate_table. qdisc_rtab_list is a single global (not per-netns), so the corrupted object is shared system-wide. BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160 qdisc_put_rtab+0x12f/0x160 tcf_police_init+0xda9/0x1590 tcf_action_init_1+0x460/0x6b0 tcf_action_init+0x439/0xa40 tcf_exts_validate_ex+0x42d/0x550 fl_change+0xddd/0x7da0 tc_new_tfilter+0xaa7/0x2420 rtnetlink_rcv_msg+0x95e/0xe90 which belongs to the cache kmalloc-2k of size 2048 Protect qdisc_rtab_list and the refcount with a dedicated spinlock. The (sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before taking the lock; if a concurrent inserter added an identical table in the meantime the freshly allocated one is freed under the lock, so no duplicate is leaked. qdisc_put_rtab() now decrements the refcount and unlinks under the same lock.
02KernelScan AI Analysis
Risk summary
A race condition in the Linux kernel's traffic control subsystem allows a local attacker to trigger a use-after-free on a globally shared rate table object. By sending concurrent netlink requests to add flower filters with police actions using the same rate, an unprivileged user can corrupt kernel heap memory, potentially leading to privilege escalation or system crash.
Vulnerability analysis
A global linked list and non-atomic reference counter for rate tables in the traffic control subsystem were protected only by the RTNL mutex, but the flower classifier can operate without that lock. Two concurrent netlink requests adding flower filters with police actions using the same rate table race on the shared list and refcount, leading to a use-after-free or double-free of a heap object. The fix adds a dedicated spinlock to serialize all lookups, insertions, and reference count updates on the rate table list, with allocations performed before taking the lock to avoid sleeping while locked. The vulnerable path is reachable from a local process via netlink without requiring root privileges, as traffic control filter operations can be performed with CAP_NET_ADMIN obtainable in a user namespace.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 5.1 | 5.10.266 | 1b050d09dd1a |
| 5.15 | 5.1 | 5.15.217 | 6e0241f6cbb1 |
| 6.6 | 5.1 | 6.6.153 | 4131dd0b6f67 |
| 6.18 | 5.1 | 6.18.46 | 8ddc2eb0d2da |
| 6.1 | 5.1 | 6.1.184 | f93c89392bd3 |
| 7.1 | 5.1 | 7.1.6 | fb29e1b41052 |
| 6.12 | 5.1 | 6.12.105 | d981098b7675 |
| mainline | 5.1 | 7.2 | f43ee0c0730d |