Junglewise Threat Intelligence

CVE-2026-31422: Linux Kernel NULL pointer dereference in net/sched cls_flow

CVE-2026-31422 · Severity: medium · CVSS 5.5 · Published 2026-04-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when configuring specific network traffic filters on shared resources, leading to a system failure (NULL pointer dereference). This impact is limited to system availability and does not directly expose sensitive data.

Technical details

A NULL pointer dereference exists in net/sched/cls_flow.c within the flow_change() function. The vulnerability is triggered when tcf_block_q() is called on a shared block, which returns NULL because shared blocks do not have an associated Qdisc. Subsequent dereferencing of this NULL pointer to access q->handle results in a kernel panic. An attacker with local privileges can exploit this by creating a flow filter without a fully qualified baseclass on a shared block via rtnetlink. The fix involves checking if a block is shared using tcf_block_shared() and returning -EINVAL if a baseclass is not specified.

Affected products

  • Linux Linux Kernel 4.15 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.168, 6.2 to 6.6.134, 6.7 to 6.12.81, 6.13 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-02: patched: Initial patch committed to mainline

References