Modified
Published: 03 Apr 2026, 15:15
Last modified:11 May 2026, 22:06

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.13% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Apr 2026, 15:15
Published
Vulnerability first disclosed
11 May 2026, 22:06
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections. This is not proper, a conversion from a ref to a locked netdev must include a liveness check (a check if the netdev hasn't been unregistered already). Fix the read cases (those under RCU). Writes needs a separate change to protect from creating the hierarchy after flush has already run.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.13% Percentile: 3%

Affected Systems

  • linuxlinux

    ≥ 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb, < 581eee0890a8bde44f1fb78ad3e70502a897d583 | ≥ 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb, < 348758ba74e6a348299965b16a97cfb817545cc0 | ≥ 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb, < 0f9ea7141f365b4f27226898e62220fb98ef8dc6 | 6.13

  • linuxlinux kernel

    ≥ 6.13.1, < 6.18.20 | ≥ 6.19, < 6.19.10 | 6.13 | 7.0:rc1 | 7.0:rc2 | 7.0:rc3 | 7.0:rc4 | 7.0:rc5 | 7.0:rc6 | 7.0:rc7

References (3)