Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system reconfigures network hardware queues while under heavy traffic, leading to a memory error. This affects systems running Linux, including certain industrial control equipment from Siemens.
Technical details
A use-after-free (UAF) vulnerability exists in net/sched due to a race condition between qdisc_reset_all_tx_gt() and the dequeue path for lockless qdiscs. When netif_set_real_num_tx_queues() is called to shrink TX queues, it triggers a reset of the qdiscs. Because lockless qdiscs use qdisc->seqlock for serialization instead of the standard qdisc_lock(), qdisc_reset() could run concurrently with __qdisc_run(), freeing socket buffers (skbs) while they were still being accessed for dequeue. This local vulnerability requires the ability to trigger network interface reconfiguration (e.g., via ethtool) or occurs during high-traffic queue adjustments. The fix involves properly acquiring the seqlock for TCQ_F_NOLOCK qdiscs during the reset process.
Affected products
- Linux Linux Kernel 6.14 and earlier
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-02-28: patched: Initial fix authored by Koichiro Den
- 2026-03-25: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/5bb27ad54d12de67e457d7d251198e361bef835e
- https://git.kernel.org/stable/c/5bc4e69306ed7ae02232eb4c0b23ed621a26d504
- https://git.kernel.org/stable/c/7594467c49bfc2f4644dee0415ac2290db11fa0d
- https://git.kernel.org/stable/c/7f083faf59d14c04e01ec05a7507f036c965acf8
- https://git.kernel.org/stable/c/8314944cc3bdeaa5a73e6f8a8cf0d94822e625cb
- https://git.kernel.org/stable/c/c69df4e0524f8de8e176ba389acd83e85f5f49d0
- https://git.kernel.org/stable/c/dbd58b0730aa06ab6ad26079cf9a5b6b58e7e750