net/sched: act_gate: snapshot parameters with RCU on replace
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_gate: snapshot parameters with RCU on replace
The gate action can be replaced while the hrtimer callback or dump path is
walking the schedule list.
Convert the parameters to an RCU-protected snapshot and swap updates under
tcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits
the entry list, preserve the existing schedule so the effective state is
unchanged.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://git.kernel.org/stable/c/035d0d09d5ab3ed3e93d18cde2b562a6719eea23https://git.kernel.org/stable/c/04d75529dc0f9be78786162ebab7424af4644df2https://git.kernel.org/stable/c/58b162e318d0243ad2d7d92456c0873f2494c351https://git.kernel.org/stable/c/62413a9c3cb183afb9bb6e94dd68caf4e4145f4chttps://git.kernel.org/stable/c/8b1251bbf0f10ac745ed74bad4d3b433caa1eeaehttps://git.kernel.org/stable/c/dfc314d7c767e350f78a46a8f8b134f80e8ad432https://git.kernel.org/stable/c/fc98fd8d214693be91253d9a88cdf8e5e143d124