CVE-2026-23245

Source
https://cve.org/CVERecord?id=CVE-2026-23245
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23245.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23245
Downstream
Published
2026-03-18T10:05:07.406Z
Modified
2026-04-14T03:48:12.896336Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net/sched: act_gate: snapshot parameters with RCU on replace
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_gate: snapshot parameters with RCU on replace

The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list.

Convert the parameters to an RCU-protected snapshot and swap updates under tcflock, freeing the previous snapshot via callrcu(). When REPLACE omits the entry list, preserve the existing schedule so the effective state is unchanged.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23245.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a51c328df3106663879645680609eb49b3ff6444
Fixed
8b1251bbf0f10ac745ed74bad4d3b433caa1eeae
Fixed
dfc314d7c767e350f78a46a8f8b134f80e8ad432
Fixed
035d0d09d5ab3ed3e93d18cde2b562a6719eea23
Fixed
04d75529dc0f9be78786162ebab7424af4644df2
Fixed
58b162e318d0243ad2d7d92456c0873f2494c351
Fixed
62413a9c3cb183afb9bb6e94dd68caf4e4145f4c

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23245.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.18
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23245.json"