CVE-2026-53080

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
24/06/2026
Last modified:
23/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/sched: cls_fw: fix NULL dereference of "old" filters before change()<br /> <br /> Like pointed out by Sashiko [1], since commit ed76f5edccc9 ("net: sched:<br /> protect filter_chain list with filter_chain_lock mutex") TC filters are<br /> added to a shared block and published to datapath before their -&gt;change()<br /> function is called. This is a problem for cls_fw: an invalid filter<br /> created with the "old" method can still classify some packets before it<br /> is destroyed by the validation logic added by Xiang.<br /> Therefore, insisting with repeated runs of the following script:<br /> <br /> # ip link add dev crash0 type dummy<br /> # ip link set dev crash0 up<br /> # mausezahn crash0 -c 100000 -P 10 \<br /> &gt; -A 4.3.2.1 -B 1.2.3.4 -t udp "dp=1234" -q &amp;<br /> # sleep 1<br /> # tc qdisc add dev crash0 egress_block 1 clsact<br /> # tc filter add block 1 protocol ip prio 1 matchall \<br /> &gt; action skbedit mark 65536 continue<br /> # tc filter add block 1 protocol ip prio 2 fw<br /> # ip link del dev crash0<br /> <br /> can still make fw_classify() hit the WARN_ON() in [2]:<br /> <br /> WARNING: ./include/net/pkt_cls.h:88 at fw_classify+0x244/0x250 [cls_fw], CPU#18: mausezahn/1399<br /> Modules linked in: cls_fw(E) act_skbedit(E)<br /> CPU: 18 UID: 0 PID: 1399 Comm: mausezahn Tainted: G E 7.0.0-rc6-virtme #17 PREEMPT(full)<br /> Tainted: [E]=UNSIGNED_MODULE<br /> Hardware name: Red Hat KVM, BIOS 1.16.3-2.el9 04/01/2014<br /> RIP: 0010:fw_classify+0x244/0x250 [cls_fw]<br /> Code: 5c 49 c7 45 00 00 00 00 00 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 5b b8 ff ff ff ff 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 90 0b 90 eb a0 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90<br /> RSP: 0018:ffffd1b7026bf8a8 EFLAGS: 00010202<br /> RAX: ffff8c5ac9c60800 RBX: ffff8c5ac99322c0 RCX: 0000000000000004<br /> RDX: 0000000000000001 RSI: ffff8c5b74d7a000 RDI: ffff8c5ac8284f40<br /> RBP: ffffd1b7026bf8d0 R08: 0000000000000000 R09: ffffd1b7026bf9b0<br /> R10: 00000000ffffffff R11: 0000000000000000 R12: 0000000000010000<br /> R13: ffffd1b7026bf930 R14: ffff8c5ac8284f40 R15: 0000000000000000<br /> FS: 00007fca40c37740(0000) GS:ffff8c5b74d7a000(0000) knlGS:0000000000000000<br /> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br /> CR2: 00007fca40e822a0 CR3: 0000000005ca0001 CR4: 0000000000172ef0<br /> Call Trace:<br /> <br /> tcf_classify+0x17d/0x5c0<br /> tc_run+0x9d/0x150<br /> __dev_queue_xmit+0x2ab/0x14d0<br /> ip_finish_output2+0x340/0x8f0<br /> ip_output+0xa4/0x250<br /> raw_sendmsg+0x147d/0x14b0<br /> __sys_sendto+0x1cc/0x1f0<br /> __x64_sys_sendto+0x24/0x30<br /> do_syscall_64+0x126/0xf80<br /> entry_SYSCALL_64_after_hwframe+0x77/0x7f<br /> RIP: 0033:0x7fca40e822ba<br /> Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89<br /> RSP: 002b:00007ffc248a42c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c<br /> RAX: ffffffffffffffda RBX: 000055ef233289d0 RCX: 00007fca40e822ba<br /> RDX: 000000000000001e RSI: 000055ef23328c30 RDI: 0000000000000003<br /> RBP: 000055ef233289d0 R08: 00007ffc248a42d0 R09: 0000000000000010<br /> R10: 0000000000000000 R11: 0000000000000246 R12: 000000000000001e<br /> R13: 00000000000186a0 R14: 0000000000000000 R15: 00007fca41043000<br /> <br /> irq event stamp: 1045778<br /> hardirqs last enabled at (1045784): [] __up_console_sem+0x52/0x60<br /> hardirqs last disabled at (1045789): [] __up_console_sem+0x37/0x60<br /> softirqs last enabled at (1045426): [] __alloc_skb+0x207/0x260<br /> softirqs last disabled at (1045434): [] __dev_queue_xmit+0x78/0x14d0<br /> <br /> Then, because of the value in the packet&amp;#39;s mark, dereference on &amp;#39;q-&gt;handle&amp;#39;<br /> with NULL &amp;#39;q&amp;#39; occurs:<br /> <br /> BUG: kernel NULL pointer dereference, address: 0000000000000038<br /> [...]<br /> RIP: 0010:fw_classify+0x1fe/0x250 [cls_fw]<br /> [...]<br /> <br /> Skip "old-style" classification on shared blocks, so that the NULL<br /> dereference is fixed and WARN_ON() is not hit anymore in the short<br /> lifetime of invalid cls_fw "old-style" filters.<br /> <br /> [1] https://sashiko.dev/#/patchset/2<br /> ---truncated---

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.1 (including) 5.10.259 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.210 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.93 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.35 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)