{"id":"CVE-2026-98235","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: release tail references on DELACTION failure\n\nA batched RTM_DELACTION request takes a temporary reference on each\naction before attempting any delet…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: release tail references on DELACTION failure\n\nA batched RTM_DELACTION request takes a temporary reference on each\naction before attempting any delet…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= a0e947c9ccffe47d45aca793d9e7fe4f4494e381 < 9eaba16f1b6ee19b249e6afd82c27f958d441458","Linux >= a0e947c9ccffe47d45aca793d9e7fe4f4494e381 < 1be63e4579af408d596f0f3165faf1a880631d3b","Linux >= a0e947c9ccffe47d45aca793d9e7fe4f4494e381 < 57b477e46ef2df3483f3488cc713c61c4b384aab","Linux >= a0e947c9ccffe47d45aca793d9e7fe4f4494e381 < 6e05e46fa821a5c1b281355f1f622ac76cb6080a","Linux 6.8"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:11.203","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98235","references":[{"url":"https://git.kernel.org/stable/c/1be63e4579af408d596f0f3165faf1a880631d3b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57b477e46ef2df3483f3488cc713c61c4b384aab","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e05e46fa821a5c1b281355f1f622ac76cb6080a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9eaba16f1b6ee19b249e6afd82c27f958d441458","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.436Z","slug":"CVE-2026-98235","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: release tail references on DELACTION failure\n\nA batched RTM_DELACTION request takes a temporary reference on each\naction before attempting any deletion. tcf_action_delete() clears\neach processed slot and drops its temporary reference before attempting\nthe deletion. If deletion fails, tca_action_gd() calls\ntcf_action_put_many() to release the remaining references, but its\ntcf_act_for_each_action() iterator stops at the first NULL slot.\n\nWhen a batch stops at an action bound to a filter, this leaks a\nreference on each subsequent action. A later delete of an unbound\naction can then return success without removing it from the IDR.\n\nWalk the full array in tcf_action_put_many() and skip NULL slots to\nrelease the references held on the unprocessed actions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}