Junglewise Threat Intelligence

CVE-2026-68138: Linux kernel net/sched use-after-free in qdisc rate table management

CVE-2026-68138 · Severity: high · CVSS 7.8 · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's network packet scheduling subsystem has a race condition in its rate-table management code that can lead to use-after-free memory errors. When network administrators apply traffic control policies (such as police actions in network filters) from multiple concurrent requests, the kernel can incorrectly free memory that is still in use, potentially causing system crashes or undefined behavior affecting network performance.

Technical details

A use-after-free vulnerability exists in the qdisc_get_rtab() and qdisc_put_rtab() functions in the Linux kernel's net/sched subsystem. These functions manipulate a global singly linked list (qdisc_rtab_list) and a non-atomic reference counter without proper locking. Historically this was safe because all callers held the RTNL mutex, but the cls_flower classifier now operates without RTNL locks (TCF_PROTO_OPS_DOIT_UNLOCKED flag), allowing concurrent access from tcf_police_init(). Two concurrent RTM_NEWTFILTER requests on different CPUs adding flower filters with police actions using the same rate table race on list mutations and the refcount, triggering a double-free of the kmalloc-2k qdisc_rate_table structure. The fix serializes access to qdisc_rtab_list and its refcount with a dedicated spinlock, with allocation performed before lock acquisition to avoid holding the lock during sleeping operations.

Affected products

  • Linux Linux kernel versions prior to the fix (exact range not specified in advisory)

Timeline

  • 2026-08-10: disclosed: CVE-2026-68138 published
  • patched: Fix applied to serialize qdisc_rtab_list with spinlock

Related threats