Junglewise Threat Intelligence

CVE-2026-64054: Linux Kernel double free in net_shaper_nl_group_doit

CVE-2026-64054 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's network shaper component, which manages how network traffic is prioritized and throttled. By providing specially crafted duplicate requests, a local user could trigger a system crash or instability. This issue primarily affects system availability and could be used to disrupt network operations.

Technical details

A double-free vulnerability exists in net/shaper/shaper.c within the net_shaper_nl_group_doit() function. The issue arises because the function fails to deduplicate NET_SHAPER_A_LEAVES entries provided by userspace. When a user provides the same leaf handle multiple times, the same parent pointer is stored twice in the old_nodes array, causing the cleanup loop to attempt to free the same memory address twice. An attacker with local access to the Netlink interface can exploit this to cause a kernel panic or potentially achieve further memory corruption. The fix introduces net_shaper_parse_leaves() to explicitly reject duplicate leaf handles.

Affected products

  • Linux Linux Kernel 6.13 to 7.1

Timeline

  • 2026-05-10: disclosed: Initial patch submitted by Jakub Kicinski
  • 2026-06-01: patched: Patch committed to stable trees
  • 2026-07-19: advisory: CVE published

References

Related threats