CVE-2026-23245

medium

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Convert the parameters to an RCU-protected snapshot and swap updates under tcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits the entry list, preserve the existing schedule so the effective state is unchanged.

References

https://git.kernel.org/stable/c/62413a9c3cb183afb9bb6e94dd68caf4e4145f4c

https://git.kernel.org/stable/c/58b162e318d0243ad2d7d92456c0873f2494c351

https://git.kernel.org/stable/c/04d75529dc0f9be78786162ebab7424af4644df2

Details

Source: Mitre, NVD

Published: 2026-03-18

Updated: 2026-03-18

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00017