CVE-2026-98235
Description
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_api: release tail references on DELACTION failure
A batched RTM_DELACTION request takes a temporary reference on each action before attempting any deletion. tcf_action_delete() clears each processed slot and drops its temporary reference before attempting the deletion. If deletion fails, tca_action_gd() calls tcf_action_put_many() to release the remaining references, but its tcf_act_for_each_action() iterator stops at the first NULL slot.
When a batch stops at an action bound to a filter, this leaks a reference on each subsequent action. A later delete of an unbound action can then return success without removing it from the IDR.
Walk the full array in tcf_action_put_many() and skip NULL slots to release the references held on the unprocessed actions.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.