Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when configuring specific network traffic filters on shared resources, leading to a system failure (NULL pointer dereference). This impact is limited to system availability and does not directly expose sensitive data.
Technical details
A NULL pointer dereference exists in net/sched/cls_flow.c within the flow_change() function. The vulnerability is triggered when tcf_block_q() is called on a shared block, which returns NULL because shared blocks do not have an associated Qdisc. Subsequent dereferencing of this NULL pointer to access q->handle results in a kernel panic. An attacker with local privileges can exploit this by creating a flow filter without a fully qualified baseclass on a shared block via rtnetlink. The fix involves checking if a block is shared using tcf_block_shared() and returning -EINVAL if a baseclass is not specified.
Affected products
- Linux Linux Kernel 4.15 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.168, 6.2 to 6.6.134, 6.7 to 6.12.81, 6.13 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory
- 2026-04-02: patched: Initial patch committed to mainline
References
- https://git.kernel.org/stable/c/1a280dd4bd1d616a01d6ffe0de284c907b555504
- https://git.kernel.org/stable/c/415ea0c973c754b9f375225807810eb9045f4293
- https://git.kernel.org/stable/c/4a09f72007201c9f667dc47f64517ec23eea65e5
- https://git.kernel.org/stable/c/57f94ac7e953eece5ed4819605a18f3cdfc63dcc
- https://git.kernel.org/stable/c/942813276edeb1741fa5b0a73471beb4e495fa08
- https://git.kernel.org/stable/c/9bf5fc36a43f7b8b5507c96e74fb81f1e8b4957e
- https://git.kernel.org/stable/c/a208c3e1232997e9317887294c20008dfcb75449