← All Advisories

CVE-2026-97616

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97616

Key Details

CVECVE-2026-97616
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_api: release all action references on NEWACTION failure

When a batched RTM_NEWACTION request replaces an existing action,

tcf_idr_check_alloc() takes a temporary reference on it. If a later

action fails to initialize, tcf_action_destroy() uses strict release

semantics to clean up the actions initialized so far. For an action

bound to a filter, the strict check returns -EPERM without dropping

the temporary reference.

This error also makes tcf_action_destroy() return before releasing

subsequent entries. Any new action initialized between the bound

action and the failing entry is leaked together with its reserved

IDR slot, preventing reuse of its index.

Use tcf_idr_release() to drop each reference held by the batch without

rejecting bound actions. This allows cleanup to continue through all

initialized entries and preserves the module reference release when

an action is destroyed. Explicit action deletion and flushing retain

their separate bind-count checks. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97616
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97616