Junglewise Threat Intelligence

CVE-2026-90071: Linux kernel net/sched sch_teql use-after-free in skb->dev handling

CVE-2026-90071 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's traffic scheduling module (sch_teql) fails to properly restore a network packet's device pointer when transmission through one network slave fails. This causes the packet to retain a stale reference to a deleted network device, leading to a use-after-free memory error that can crash the system or enable privilege escalation when the stale reference is dereferenced during later packet processing.

Technical details

The vulnerability is a use-after-free (CWE-416) in the Linux kernel's teql_master_xmit() function within the traffic scheduler (net/sched/sch_teql.c). When transmitting a packet through multiple slave network interfaces, the function sets skb->dev to each slave before calling its ndo_start_xmit() handler, but fails to restore skb->dev to the master when transmission fails. If a subsequent slave has an unresolved neighbor, the queued packet retains the stale device pointer. When the previous slave device is deleted, the reference becomes a use-after-free that can be triggered when ARP resolution completes or times out, leading to memory corruption and potential code execution. The attack requires local access to trigger network device deletion and transmission failures, but no authentication or user interaction is needed once network access is available.

Affected products

  • Linux Linux kernel 7.2.0-rc6 and likely earlier versions

Timeline

  • 2026-09-17: disclosed

Related threats