Executive brief
The Linux kernel's traffic control (tc) packet edit action module contains a race condition that allows a privileged attacker to write out-of-bounds to heap memory. The vulnerability exists in the network scheduling subsystem used for packet filtering and manipulation. Exploitation results in heap memory corruption that can affect kernel stability or enable further privilege escalation attacks.
Technical details
The vulnerability is a Time-Of-Check-Time-Of-Use (TOCTOU) race condition in the act_pedit module's tcf_pedit_offload_act_setup() function. Between allocating a flow_rule buffer based on a key count and filling that buffer, a concurrent thread can modify the pedit action's key parameters, causing an out-of-bounds write. The root cause is insufficient synchronization between the flower classifier (which operates unlocked via TCF_PROTO_OPS_DOIT_UNLOCKED) and RTM_NEWACTION operations (which hold RTNL lock), creating independent locking domains. The fix introduces proper locking via tcf_pedit_nkeys_locked() which reads key counts under act->tcfa_lock, and adds capacity checks to prevent silent truncation. Exploitation requires CAP_NET_ADMIN capability.
Affected products
- Linux Linux kernel multiple versions (race condition in net/sched/act_pedit.c)
Timeline
- 2026-08-15: disclosed
- 2026-07-01: patched: Fix commit 8b519cbcabe836a441369fbec1a8a6518a709251 by Jamal Hadi Salim