← All Advisories

CVE-2026-98017

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98017

Key Details

CVECVE-2026-98017
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net/sched: defer qdisc freeing after failed creation

An RTM_NEWQDISC request can make clsact bind a populated shared ingress

block during ->init(), publishing an embedded mini_Qdisc to lockless

readers. If the same request has an invalid TCA_RATE, estimator setup

fails after ->init(); the unwind removes the pointer but synchronously

frees its containing qdisc while tc_run() may still hold it.

Retire failed qdiscs through the same RCU helper as normal destruction.

Inline the synchronous free into the callback now that no direct callers

remain. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98017
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98017