Junglewise Threat Intelligence

CVE-2026-72035: Linux kernel sch_taprio NULL pointer dereference in packet dequeue

CVE-2026-72035 · Severity: high · CVSS 8.2 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's taprio traffic scheduler contains a flaw in how it retrieves network packets from child queue management disciplines. When using certain queue types (like qfq), the scheduler incorrectly bypasses buffered packets, causing the kernel to crash with a NULL pointer error during normal network transmission. This can disrupt network services and cause system instability on affected servers.

Technical details

The vulnerability is a NULL pointer dereference in the taprio qdisc scheduler (net/sched/sch_taprio.c). When the software path peeks at a non-work-conserving child qdisc, the child stashes the peeked skb in its gso_skb field. The vulnerable code then calls child->ops->dequeue() directly, which ignores this stash, orphans the peeked skb, and desyncs the child's qlen/backlog counters. With a qfq child qdisc, this causes re-entry on an emptied list and results in NULL pointer dereference from softirq context during egress packet processing. The fix replaces the direct dequeue call with qdisc_dequeue_peeked(), which properly retrieves the stashed packet first. Attack vector is local/adjacent (kernel network processing path), no authentication required. Patch is available in upstream kernel and stable branches.

Affected products

  • Linux Linux kernel prior to e056e1dfcddca877dd46d704e8ec9860cfc9ec44

Timeline

  • 2026-08-15: disclosed
  • 2026-07-28: patched: Upstream fix committed; stable branch backports followed

References

Related threats