Junglewise Threat Intelligence

CVE-2026-64530: Linux Kernel use-after-free in tcf_qevent_handle

CVE-2026-64530 · Severity: info · CVSS 0 · Published 2026-07-26

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a remote attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system processes specific types of fragmented network traffic, leading to a memory error known as a 'use-after-free.' This affects systems using the Random Early Detection (RED) congestion control mechanism and could impact network stability and service availability.

Technical details

A use-after-free (UAF) vulnerability exists in net/sched/cls_api.c within the tcf_qevent_handle function. The root cause is the failure to handle the TC_ACT_CONSUMED return action from tcf_classify(). When the defragmentation engine (act_ct) holds an skb (socket buffer) due to out-of-order fragments, it returns TC_ACT_CONSUMED, indicating the caller no longer owns the buffer. Because tcf_qevent_handle fell through this case, it returned the skb to the caller (specifically the RED qdisc), which then attempted to operate on the unowned memory. This can be triggered by a fragmented UDP stream when RED qevents are configured. Patches have been released across multiple stable kernel branches to correctly treat TC_ACT_CONSUMED as a 'stolen' packet.

Affected products

  • Linux Linux Kernel 3f14b377d01d to a8a02897f2b479127db261de05cbf0c28b98d159

Timeline

  • 2026-06-20: disclosed: Initial patch submitted by Jamal Hadi Salim
  • 2026-07-24: patched: Commits merged into stable branches by Greg Kroah-Hartman
  • 2026-07-26: advisory: CVE-2026-64530 published

References

Related threats