net/sched: cls_route: fix fastmap use-after-free on filter
Summary
| CVE | CVE-2026-74583 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-21 17:16:44 UTC |
| Updated | 2026-08-21 17:16:44 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_route: fix fastmap use-after-free on filter
The route4 classifier maintains a 16-slot fastmap cache that stores raw
struct route4_filter pointers indexed by (id, iif). The reader
(route4_classify) populates this cache via route4_set_fastmap() for every
classified packet that hits a filter. The writer (route4_delete,
route4_change) clears the cache via route4_reset_fastmap() before
RCU-deferred kfree of the filter.
This creates a UAF race:
1. Reader walks the RCU-protected bucket chain, finds filter f
2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work()
3. Reader calls route4_set_fastmap() and writes f into the cache
*after* the writer's reset, caching a pointer about to be freed
4. After the RCU grace period, kfree(f) executes
5. Next classified packet on the same (id, iif) tuple hits the stale
fastmap entry and reads f->res from freed memory
Reproduced with an mdelay(100) accelerator in route4_set_fastmap() and a
concurrent add/delete stress test (provided by both zdi and Santosh).
Both triggered KASAN slab-use-after-free reports in the route4 fastmap
paths.
Fix:
Introduce a per-filter boolean dying flag to suppress stale fastmap
republishing by in-flight readers. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 7897198b26445b4009a057bda1986b94a99e5d5f git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 820f083c294ad6d319c02a7d43294f2ed2565139 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 5ec9001be6d0eb527251125632ec8fe88278897f git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 b969984b2bdc85d721ce4047cd270cd37ec705a2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 a17f636c9330eac879822ce29f998e5abd1b72c1 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 0e7a8cf8895b06d07c7311f028eba16ad742b9bc git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 ae9aff87025219005a2d16b4fe83d6f24643e50d git |
Not specified |
| CNA |
Linux |
Linux |
affected 1109c00547fc66df45b9ff923544be4c1e1bec13 47d7f7051253bdc02b1d245d87e38f16d31a74df git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.265 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.216 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.183 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.152 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.104 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.45 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.9 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/7897198b26445b4009a057bda1986b94a99e5d5f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0e7a8cf8895b06d07c7311f028eba16ad742b9bc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b969984b2bdc85d721ce4047cd270cd37ec705a2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/47d7f7051253bdc02b1d245d87e38f16d31a74df |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/820f083c294ad6d319c02a7d43294f2ed2565139 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ae9aff87025219005a2d16b4fe83d6f24643e50d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5ec9001be6d0eb527251125632ec8fe88278897f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a17f636c9330eac879822ce29f998e5abd1b72c1 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.