Junglewise Threat Intelligence

CVE-2026-53011: Linux Kernel use-after-free in taprio scheduler during schedule switch

CVE-2026-53011 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the 'taprio' traffic scheduler used for time-sensitive networking. When the system switches between different traffic schedules, it could mistakenly access memory that has already been freed. This type of flaw typically leads to system instability, unpredictable network behavior, or a complete system crash (denial of service).

Technical details

A use-after-free vulnerability exists in net/sched/sch_taprio.c within the advance_sched() function. When should_change_schedules() returns true, the switch_schedules() function promotes an 'admin' schedule to 'oper' and queues the old 'oper' schedule for RCU freeing. However, the 'next' pointer continues to reference an entry from the now-freed old schedule. Subsequent operations, such as setting next->end_time and rcu_assign_pointer, access this freed memory. The fix ensures that the 'next' pointer is updated to the first entry of the new 'oper' schedule immediately after the switch. This issue affects systems utilizing the Time Aware Priority Shaper (taprio) for deterministic networking.

Affected products

  • Linux Linux Kernel a3d43c0d56f1b94e74963a2fbadfb70126d92213 to 105425b1969c5affe532713cfac1c0b320d7ac2b

Timeline

  • 2026-04-10: disclosed: Vulnerability fix authored
  • 2026-06-24: advisory: NVD publication date

References

Related threats