In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Convert the parameters to an RCU-protected snapshot and swap updates under tcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits the entry list, preserve the existing schedule so the effective state is unchanged.
https://git.kernel.org/stable/c/62413a9c3cb183afb9bb6e94dd68caf4e4145f4c
https://git.kernel.org/stable/c/58b162e318d0243ad2d7d92456c0873f2494c351
https://git.kernel.org/stable/c/04d75529dc0f9be78786162ebab7424af4644df2