PatchSiren cyber security CVE debrief
CVE-2026-68138 Linux CVE debrief
The Linux kernel's net/sched module is vulnerable to a use-after-free / double-free exploit due to a race condition in qdisc_rtab_list and a non-atomic refcnt. This is caused by cls_flower setting TCF_PROTO_OPS_DOIT_UNLOCKED, leading to tc_new_tfilter() keeping rtnl_held == false. The bug affects the kmalloc-2k struct qdisc_rate_table and can lead to system-wide corruption. Linux kernel users, administrators, and security teams should be aware of this vulnerability and prioritize patching to prevent potential exploitation.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-23
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-23
Who should care
Linux kernel users, administrators, and security teams should be aware of this vulnerability and prioritize patching to prevent potential exploitation. Affected operators, platforms, and vulnerability-management teams should review and update Linux kernel installations to ensure the patched version is deployed. Security teams should monitor system logs for potential exploitation attempts and review compensating controls for exposed systems while remediation is scheduled and verified. Asset inventory and rollback/change windows should also be reviewed to ensure the patched version is deployed. Source tracking and exposure review should be performed to identify potential vulnerabilities. Monitoring and detection should be reviewed to identify potential exploitation attempts. Compensating controls should be reviewed to ensure that they are effective in preventing exploitation. Rollback/change windows should be reviewed to ensure that the patched version is deployed in a timely manner. Asset inventory should be reviewed to ensure that all affected systems are identified and patched. Vendor patch guidance should be followed to ensure that the patched version is deployed correctly. Exposure review should be performed to identify potential vulnerabilities. Compensating controls should be reviewed to ensure that they are effective in preventing exploitation. Monitoring and detection should be reviewed to identify potential exploitation attempts. Source tracking should be performed to identify potential vulnerabilities. Asset inventory and rollback/change windows should be reviewed to ensure that the patched version is deployed in a timely manner. Vendor patch guidance should be followed to ensure that the patched version is deployed correctly. Exposure review should be performed to identify potential vulnerabilities. Compensating controls should be reviewed to ensure that they are effective in preventing exploitation. Monitoring and detection should be reviewed to identify potential exploitation attempts. Source tracking should be performed to identify potential vulnerabilities. Asset inventory and rollback/change windows should be reviewed to ensure that the patched A
Technical summary
The Linux kernel's net/sched module is vulnerable to a use-after-free / double-free exploit due to a race condition in qdisc_rtab_list and a non-atomic refcnt. This is caused by cls_flower setting TCF_PROTO_OPS_DOIT_UNLOCKED, leading to tc_new_tfilter() keeping rtnl_held == false. The bug affects the kmalloc-2k struct qdisc_rate_table and can lead to system-wide corruption. The vulnerability has a high CVSS score of 7.8 and is classified as HIGH severity.
Defensive priority
This vulnerability has a high CVSS score of 7.8 and is classified as HIGH severity. Linux kernel users should prioritize patching.
Recommended defensive actions
- Apply the official patch from the Linux kernel maintainers.
- Review and update Linux kernel installations to ensure the patched version is deployed.
- Monitor system logs for potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Perform source tracking to identify potential vulnerabilities.
Evidence notes
The CVE is related to a use-after-free / double-free vulnerability in the Linux kernel's net/sched module. A race condition in qdisc_rtab_list and a non-atomic refcnt allow for exploitation. The bug was introduced when cls_flower started setting TCF_PROTO_OPS_DOIT_UNLOCKED, causing tc_new_tfilter() to keep rtnl_held == false. This leads to a potential system-wide corruption of the kmalloc-2k struct qdisc_rate_table.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68138 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68138
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68138 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68138
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fb29e1b41052488ee3f2d115d4a870497ebd7f7d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.