Junglewise Threat Intelligence

CVE-2026-53264: Linux Kernel use-after-free in net/sched act_api

CVE-2026-53264 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's network scheduling component. This flaw could allow a local attacker to trigger a 'use-after-free' error by simultaneously creating and deleting network filters. In practice, this could lead to system instability, crashes, or potentially unauthorized access to kernel memory.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's net/sched act_api due to improper lifecycle management of actions. When NEWTFILTER and DELFILTER are run concurrently, a race condition occurs where one CPU can find an action in the IDR while another CPU decrements the reference count to zero and immediately frees the memory using kfree() without waiting for an RCU grace period. This allows the first CPU to attempt to increment the reference count on already freed memory. The fix involves restoring RCU-deferred freeing by adding a struct rcu_head to tc_action and utilizing kfree_rcu() to ensure memory is not reclaimed until all RCU readers have finished.

Affected products

  • Linux Linux Kernel versions prior to fixed stable releases in June 2026

Timeline

  • 2026-05-31: other: Patch authored by Jamal Hadi Salim
  • 2026-06-25: disclosed: CVE published

References

Related threats