Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Convert the parameters to an RCU-protected snapshot and swap updates under tcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits the entry list, preserve the existing schedule so the effective state is unchanged.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.8.1, < 5.10.253 |
References
- https://git.kernel.org/stable/c/035d0d09d5ab3ed3e93d18cde2b562a6719eea23Patch
- https://git.kernel.org/stable/c/04d75529dc0f9be78786162ebab7424af4644df2Patch
- https://git.kernel.org/stable/c/58b162e318d0243ad2d7d92456c0873f2494c351Patch
- https://git.kernel.org/stable/c/62413a9c3cb183afb9bb6e94dd68caf4e4145f4cPatch
- https://git.kernel.org/stable/c/8b1251bbf0f10ac745ed74bad4d3b433caa1eeaePatch
- https://git.kernel.org/stable/c/dfc314d7c767e350f78a46a8f8b134f80e8ad432Patch
- https://git.kernel.org/stable/c/fc98fd8d214693be91253d9a88cdf8e5e143d124Patch
FAQ
What is CVE-2026-23245?
CVE-2026-23245 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump pa...
How severe is CVE-2026-23245?
CVE-2026-23245 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23245?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.