Junglewise Threat Intelligence

CVE-2026-23340: Linux Kernel use-after-free in net scheduler during qdisc reset

CVE-2026-23340 · Severity: high · CVSS 7.8 · Published 2026-03-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system reconfigures network hardware queues while under heavy traffic, leading to a memory error. This affects systems running Linux, including certain industrial control equipment from Siemens.

Technical details

A use-after-free (UAF) vulnerability exists in net/sched due to a race condition between qdisc_reset_all_tx_gt() and the dequeue path for lockless qdiscs. When netif_set_real_num_tx_queues() is called to shrink TX queues, it triggers a reset of the qdiscs. Because lockless qdiscs use qdisc->seqlock for serialization instead of the standard qdisc_lock(), qdisc_reset() could run concurrently with __qdisc_run(), freeing socket buffers (skbs) while they were still being accessed for dequeue. This local vulnerability requires the ability to trigger network interface reconfiguration (e.g., via ethtool) or occurs during high-traffic queue adjustments. The fix involves properly acquiring the seqlock for TCQ_F_NOLOCK qdiscs during the reset process.

Affected products

  • Linux Linux Kernel 6.14 and earlier
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-02-28: patched: Initial fix authored by Koichiro Den
  • 2026-03-25: advisory: NVD publication date

References

Related threats