Executive brief
A vulnerability was identified in the Linux kernel's IP Virtual Server (IPVS) component, which is used for load balancing network traffic. When an administrator modifies a service's traffic scheduler, a timing issue could cause the system to attempt to use a scheduler that has already been removed from memory. This could lead to a system crash or unpredictable behavior, potentially impacting the availability of network services.
Technical details
A use-after-free vulnerability exists in the Linux kernel IPVS (IP Virtual Server) module due to improper synchronization during scheduler updates. In `ip_vs_edit_service()`, the pointer to the old scheduler was cleared only after the scheduler module initiated RCU (Read-Copy-Update) callbacks. This allowed network packets to continue referencing the old scheduler even after its associated data (`svc->sched_data`) was freed following the RCU grace period. The fix involves clearing the scheduler pointer earlier in `ip_vs_unbind_scheduler()` and ensuring proper memory barriers are in place before RCU callbacks are triggered. Additionally, the fix improves error handling by attempting to restore the old scheduler if a new one fails to initialize.
Affected products
- Linux Linux 3.18.23 to 3.19, 4.1.11 to 4.2
Timeline
- 2026-05-25: patched: Initial patch authored by Julian Anastasov
- 2026-06-25: disclosed: CVE-2026-53270 published
References
- https://git.kernel.org/stable/c/14e4689c113b4c06af1069364ade24fdd7055f33
- https://git.kernel.org/stable/c/193989cc6d80dd8e0460fb3992e69fa03bf0ff9b
- https://git.kernel.org/stable/c/19a9493faa4bf3c7bd0a386f30b60b1bb4a3da03
- https://git.kernel.org/stable/c/25918720ba97f974a4f8d433b5a0132c5b43f6f3
- https://git.kernel.org/stable/c/7d4f5004511757e3984901ffb412fcf858d80ed5
- https://git.kernel.org/stable/c/c6376b9b1b4d2bad638256b1b3588e073344ae69
- https://git.kernel.org/stable/c/d10730a1f2caf08088e0db1b19b242f3e6fa5f06