CVE-2026-23437 PUBLISHED

net: shaper: protect late read accesses to the hierarchy

Assigner: Linux
Reserved: 13.01.2026 Published: 03.04.2026 Updated: 03.04.2026

In the Linux kernel, the following vulnerability has been resolved:

net: shaper: protect late read accesses to the hierarchy

We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections.

This is not proper, a conversion from a ref to a locked netdev must include a liveness check (a check if the netdev hasn't been unregistered already). Fix the read cases (those under RCU). Writes needs a separate change to protect from creating the hierarchy after flush has already run.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb to 581eee0890a8bde44f1fb78ad3e70502a897d583 (excl.)
  • affected from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb to 348758ba74e6a348299965b16a97cfb817545cc0 (excl.)
  • affected from 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb to 0f9ea7141f365b4f27226898e62220fb98ef8dc6 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.13 is affected
  • unaffected from 0 to 6.13 (excl.)
  • unaffected from 6.18.20 to 6.18.* (incl.)
  • unaffected from 6.19.10 to 6.19.* (incl.)
  • unaffected from 7.0-rc5 to * (incl.)

References