Junglewise Threat Intelligence

CVE-2026-23437: Linux Kernel race condition in net shaper hierarchy access

CVE-2026-23437 · Severity: high · CVSS 7.8 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash or potentially access sensitive information. The issue occurs when the system manages network traffic shaping rules for network interfaces that are being removed or unregistered. This could impact system availability and operational stability in environments where network configurations change frequently.

Technical details

A race condition exists in net/shaper/shaper.c within the Linux kernel due to improper liveness checks when converting a netdev reference to a locked state. During Netlink operations, the kernel takes a reference to a netdev during the 'pre-' callback phase, but fails to verify if the device has been unregistered before accessing its shaper hierarchy in the main callback body. This 'late read' access under RCU can lead to a use-after-free if the netdev is flushed or unregistered between the reference acquisition and the RCU lock. The fix introduces net_shaper_hierarchy_rcu() to perform a liveness check on the netdev registration state before accessing the hierarchy.

Affected products

  • Linux Linux Kernel 6.13 through 6.18.19, 6.19 through 6.19.9

Timeline

  • 2026-03-17: patched: Initial fix authored by Jakub Kicinski
  • 2026-04-03: disclosed: CVE-2026-23437 assigned and published

References

Related threats