Answer in brief
CVE-2026-90248 records a Unknown severity vulnerability in net/sched: cls_api: fix teardown of an adopted proto on insert-race loss. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8b64678e0af8f4d62a40149baedebe78503a5255 <a68e664ddf16ecae6d769d6a2eb356f8abab75c9 || >=8b64678e0af8f4d62a40149baedebe78503a5255 <df02b6dc136af45e92ee4c86f4aa6c9a60790b1e || >=8b64678e0af8f4d62a40149baedebe78503a5255 <bee2208276c8e0e40a249ffdcf6e5434a79a847c || >=8b64678e0af8f4d62a40149baedebe78503a5255 <219c87aeefdcc8c1caf28cc99e9b361ce7393d3a || >=8b64678e0af8f4d62a40149baedebe78503a5255 <bbe2fd6d77df630356185406a97317f6aa6a92cf || >=8b64678e0af8f4d62a40149baedebe78503a5255 <dc8b33b819cb02a75936940c120aa669ad89942d || >=8b64678e0af8f4d62a40149baedebe78503a5255 <d4e359b3608a0e184bbe8d61a5c3b50d0831c44a | a68e664ddf16ecae6d769d6a2eb356f8abab75c9, df02b6dc136af45e92ee4c86f4aa6c9a60790b1e, bee2208276c8e0e40a249ffdcf6e5434a79a847c, 219c87aeefdcc8c1caf28cc99e9b361ce7393d3a, bbe2fd6d77df630356185406a97317f6aa6a92cf, dc8b33b819cb02a75936940c120aa669ad89942d, d4e359b3608a0e184bbe8d61a5c3b50d0831c44a |
| Linux/Linuxgeneric | 5.1 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted proto on insert-race loss In tc_new_tfilter() the create branch sets tp_created = 1 before calling tcf_chain_tp_insert_unique(). When the caller loses the race (another request inserted a proto at the same chain/prio first), insert_unique() destroys the caller's own tp_new and returns the winner's proto with an extra reference. tp_created was never cleared, so the loser's errout path treated the winner's live proto as its own and called tcf_chain_tp_delete_empty() on it, silently unlinking an active classifier that the winning request already advertised via RTM_NEWTFILTER. Track the outcome of the insert step in a single tri-state variable so each errout path reacts correctly: - TP_NOT_CREATED: no proto created; pursue the old path. - TP_CREATED: proto inserted successfully; same code path as before. - TP_NOT_OWNED: New - lost the insert race; tp is another request's proto (chain ref already released by tp_new's destroy) Both errout reactions are single expressions derived from the state. This fix is motivated by the Sashiko's automated review of Patch (net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers) [1][2]. The review identified the silent-unlink behaviour of an adopted proto's teardown when a request loses the tcf_chain_tp_insert_unique() race. [1] https://sashiko.dev/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com [2] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260801125632.360365-1-jhs%40mojatatu.com
Quoted source text, attributed separately from HOL analysis.