← All Advisories

Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-23413

Key Details

CVECVE-2026-23413
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux Kernel
Classified asCWE-416 (Use After Free)
Exploitation prediction (EPSS)0.12% probability of exploitation in the next 30 days (2% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

clsact: Fix use-after-free in init/destroy rollback asymmetry

Fix a use-after-free in the clsact qdisc upon init/destroy rollback asymmetry.

The latter is achieved by first fully initializing a clsact instance, and

then in a second step having a replacement failure for the new clsact qdisc

instance. clsact_init() initializes ingress first and then takes care of the

egress part. This can fail midway, for example, via tcf_block_get_ext(). Upon

failure, the kernel will trigger the clsact_destroy() callback.

Commit 1cb6f0bae504 ("bpf: Fix too early release of tcx_entry") details the

way how the transition is happening. If tcf_block_get_ext on the q->ingress_block

ends up failing, we took the tcx_miniq_inc reference count on the ingress

side, but not yet on the egress side. clsact_destroy() tests whether the

{ingress,egress}_entry was non-NULL. However, even in midway failure on the

replacement, both are in fact non-NULL with a valid egress_entry from the

previous clsact instance.

What we really need to test for is whether the qdisc instance-specific ingress

or egress side previously got initialized. This adds a small helper for checking

the miniq initialization called mini_qdisc_pair_inited, and utilizes that upon

clsact_destroy() in order to fix the use-after-free scenario. Convert the

ingress_destroy() side as well so both are consistent to each other.

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-23413
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-23413