CVE-2026-98380: net/sched: reject IDR error pointers when deleting actions
In the Linux kernel, the following vulnerability has been resolved:
net/sched: reject IDR error pointers when deleting actions
tcfactiondelete() drops the reference held by its lookup before calling tcfidrdeleteindex() with the saved action index. An unlocked classifier can remove that action and reserve the same IDR slot with ERRPTR(-EBUSY) in between.
tcfidrdeleteindex() only checks the lookup result for NULL. It therefore treats the reservation as a tcaction and dereferences tcfabindcnt. A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source. KASAN reported this decoded trace:
BUG: KASAN: null-ptr-deref in tcaactiongd+0x5b9/0x1010 Read of size 4 at addr 0000000000000010 by task poc/150 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002 RIP: tcaactiongd+0x5c0/0x1010: archatomicread at arch/x86/include/asm/atomic.h:23 rawatomicread at include/linux/atomic/atomic-arch-fallback.h:457 atomicread at include/linux/atomic/atomic-instrumented.h:33 tcfidrdeleteindex at net/sched/actapi.c:766 tcfactiondelete at net/sched/actapi.c:1859 tcfdelnotify at net/sched/actapi.c:2014 tcaactiongd at net/sched/actapi.c:2064 R13: 0000000000000010 R15: fffffffffffffff0 Kernel panic - not syncing: Fatal exception
R15 contains ERRPTR(-EBUSY), and adding the tcfabindcnt offset produces the address in R13. With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic. Treat error pointers as absent and return -ENOENT.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the flaw?
The issue requires a race during deletion of a traffic-control action. After tcf_action_delete() releases its lookup reference, an unlocked classifier must remove the action and reserve the same IDR slot with ERR_PTR(-EBUSY) before tcf_idr_delete_index() uses the saved index.
What is the impact of a successful race?
tcf_idr_delete_index() can treat an ERR_PTR(-EBUSY) reservation as a valid tc_action and dereference tcfa_bindcnt. The reported result is a kernel null-pointer dereference/general protection fault, with KASAN identifying the fault in tca_action_gd through tcf_idr_delete_index().
How can an affected system be identified?
Relevant crash traces include tca_action_gd, tcf_idr_delete_index, tcf_action_delete, and tcf_del_notify. KASAN may report a null-pointer dereference reading address 0x10 during this call path.