Junglewise Threat Intelligence

CVE-2026-53270: Linux Kernel use-after-free in IPVS scheduler update

CVE-2026-53270 · Severity: info · Published 2026-06-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's IP Virtual Server (IPVS) component, which is used for load balancing network traffic. When an administrator modifies a service's traffic scheduler, a timing issue could cause the system to attempt to use a scheduler that has already been removed from memory. This could lead to a system crash or unpredictable behavior, potentially impacting the availability of network services.

Technical details

A use-after-free vulnerability exists in the Linux kernel IPVS (IP Virtual Server) module due to improper synchronization during scheduler updates. In `ip_vs_edit_service()`, the pointer to the old scheduler was cleared only after the scheduler module initiated RCU (Read-Copy-Update) callbacks. This allowed network packets to continue referencing the old scheduler even after its associated data (`svc->sched_data`) was freed following the RCU grace period. The fix involves clearing the scheduler pointer earlier in `ip_vs_unbind_scheduler()` and ensuring proper memory barriers are in place before RCU callbacks are triggered. Additionally, the fix improves error handling by attempting to restore the old scheduler if a new one fails to initialize.

Affected products

  • Linux Linux 3.18.23 to 3.19, 4.1.11 to 4.2

Timeline

  • 2026-05-25: patched: Initial patch authored by Julian Anastasov
  • 2026-06-25: disclosed: CVE-2026-53270 published

References