{"id":"CVE-2026-23245","title":"net/sched: act_gate: snapshot parameters with RCU on replace","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_gate: snapshot parameters with RCU on replace\n\nThe gate action can be replaced while the hrtimer callback or dump path is\nwalking the schedule list.\n\nCon…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= a51c328df3106663879645680609eb49b3ff6444 < fc98fd8d214693be91253d9a88cdf8e5e143d124","Linux >= a51c328df3106663879645680609eb49b3ff6444 < 8b1251bbf0f10ac745ed74bad4d3b433caa1eeae","Linux >= a51c328df3106663879645680609eb49b3ff6444 < dfc314d7c767e350f78a46a8f8b134f80e8ad432","Linux >= a51c328df3106663879645680609eb49b3ff6444 < 035d0d09d5ab3ed3e93d18cde2b562a6719eea23","Linux >= a51c328df3106663879645680609eb49b3ff6444 < 04d75529dc0f9be78786162ebab7424af4644df2","Linux >= a51c328df3106663879645680609eb49b3ff6444 < 58b162e318d0243ad2d7d92456c0873f2494c351","Linux >= a51c328df3106663879645680609eb49b3ff6444 < 62413a9c3cb183afb9bb6e94dd68caf4e4145f4c","Linux 5.8"],"published":"2026-03-18","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:45:10.126Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-23245","references":[{"url":"https://git.kernel.org/stable/c/fc98fd8d214693be91253d9a88cdf8e5e143d124"},{"url":"https://git.kernel.org/stable/c/8b1251bbf0f10ac745ed74bad4d3b433caa1eeae"},{"url":"https://git.kernel.org/stable/c/dfc314d7c767e350f78a46a8f8b134f80e8ad432"},{"url":"https://git.kernel.org/stable/c/035d0d09d5ab3ed3e93d18cde2b562a6719eea23"},{"url":"https://git.kernel.org/stable/c/04d75529dc0f9be78786162ebab7424af4644df2"},{"url":"https://git.kernel.org/stable/c/58b162e318d0243ad2d7d92456c0873f2494c351"},{"url":"https://git.kernel.org/stable/c/62413a9c3cb183afb9bb6e94dd68caf4e4145f4c"}],"tags":["cve.org"],"epss":0.00127,"epssPercentile":0.02715,"ingestedAt":"2026-09-08T15:33:26.993Z","slug":"CVE-2026-23245","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_gate: snapshot parameters with RCU on replace\n\nThe gate action can be replaced while the hrtimer callback or dump path is\nwalking the schedule list.\n\nConvert the parameters to an RCU-protected snapshot and swap updates under\ntcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits\nthe entry list, preserve the existing schedule so the effective state is\nunchanged.\n\n## Affected\n\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < fc98fd8d214693be91253d9a88cdf8e5e143d124`\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < 8b1251bbf0f10ac745ed74bad4d3b433caa1eeae`\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < dfc314d7c767e350f78a46a8f8b134f80e8ad432`\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < 035d0d09d5ab3ed3e93d18cde2b562a6719eea23`\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < 04d75529dc0f9be78786162ebab7424af4644df2`\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < 58b162e318d0243ad2d7d92456c0873f2494c351`\n- `Linux >= a51c328df3106663879645680609eb49b3ff6444 < 62413a9c3cb183afb9bb6e94dd68caf4e4145f4c`\n- `Linux 5.8`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}