CVE-2026-53270 (GCVE-0-2026-53270)
Vulnerability from cvelistv5
Published
2026-06-25 08:39
Modified
2026-08-05 12:34
Summary
In the Linux kernel, the following vulnerability has been resolved: ipvs: clear the svc scheduler ptr early on edit ip_vs_edit_service() while unbinding the old scheduler clears the svc->scheduler ptr after the scheduler module initiates RCU callbacks. This can cause packets to use the old scheduler at the time when svc->sched_data is already freed after RCU grace period. Fix it by clearing the ptr early in ip_vs_unbind_scheduler(), before the done_service method schedules any RCU callbacks. Also, if the new scheduler fails to initialize when replacing the old scheduler, try to restore the old scheduler while still returning the error code.
Impacted products
Vendor Product Version
Linux Linux Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: 05f00505a89acd21f5d0d20f5797dfbc4cf85243
Version: c803fddd2a95a70873c68dbff42d4c59fd2e674e
Version: 4ec8fb23158797affae7993c15beba080488482f
Version: 3.18.23   
Version: 4.1.11   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "include/net/ip_vs.h",
            "net/netfilter/ipvs/ip_vs_ctl.c",
            "net/netfilter/ipvs/ip_vs_sched.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d10730a1f2caf08088e0db1b19b242f3e6fa5f06",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "e4feec3174036ba772006be74beee0efa09a9eb8",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "7d4f5004511757e3984901ffb412fcf858d80ed5",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "c6376b9b1b4d2bad638256b1b3588e073344ae69",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "14e4689c113b4c06af1069364ade24fdd7055f33",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "25918720ba97f974a4f8d433b5a0132c5b43f6f3",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "19a9493faa4bf3c7bd0a386f30b60b1bb4a3da03",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "lessThan": "193989cc6d80dd8e0460fb3992e69fa03bf0ff9b",
              "status": "affected",
              "version": "05f00505a89acd21f5d0d20f5797dfbc4cf85243",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c803fddd2a95a70873c68dbff42d4c59fd2e674e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4ec8fb23158797affae7993c15beba080488482f",
              "versionType": "git"
            },
            {
              "lessThan": "3.19",
              "status": "affected",
              "version": "3.18.23",
              "versionType": "semver"
            },
            {
              "lessThan": "4.2",
              "status": "affected",
              "version": "4.1.11",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "include/net/ip_vs.h",
            "net/netfilter/ipvs/ip_vs_ctl.c",
            "net/netfilter/ipvs/ip_vs_sched.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.2"
            },
            {
              "lessThan": "4.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.94",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.36",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.259",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.176",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.143",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.94",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.36",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.13",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.18.23",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.1.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear the svc scheduler ptr early on edit\n\nip_vs_edit_service() while unbinding the old scheduler clears\nthe svc-\u003escheduler ptr after the scheduler module initiates\nRCU callbacks. This can cause packets to use the old\nscheduler at the time when svc-\u003esched_data is already freed\nafter RCU grace period.\n\nFix it by clearing the ptr early in ip_vs_unbind_scheduler(),\nbefore the done_service method schedules any RCU callbacks.\n\nAlso, if the new scheduler fails to initialize when replacing\nthe old scheduler, try to restore the old scheduler while still\nreturning the error code."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable transition is reached through local IPVS service-edit control paths such as `setsockopt(IP_VS_SO_SET_EDIT)` or IPVS generic netlink; packets exercise the stale scheduler afterward, but the attacker must initiate the local service edit.\nAC:L - The attacker can control both sides of the condition by changing the scheduler and generating new TCP/UDP/SCTP traffic to the service, so this is not dependent on an uncontrollable race.\nPR:L - The legacy setsockopt path checks `CAP_NET_ADMIN` in the socket network namespace, which is reachable by an unprivileged local user via user and network namespaces in plausible deployments.\nUI:N - No victim interaction is needed once the attacker has local access and namespace privileges; the attacker can create/edit the IPVS service and send triggering traffic.\nS:U - The impact is kernel memory corruption within the same host security authority, not a VM, IOMMU, or separate security-scope escape.\nC:H - This is an RCU use-after-free of scheduler-private `svc-\u003esched_data`, and freed scheduler state can be reused and dereferenced by packet scheduling, making high confidentiality impact defensible.\nI:H - Several affected schedulers write through the stale `sched_data` pointer, so the UAF can plausibly become arbitrary kernel memory corruption or control-flow compromise.\nA:H - At minimum the stale scheduler pointer can dereference freed scheduler state during packet processing and crash or panic the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:34:46.621Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d10730a1f2caf08088e0db1b19b242f3e6fa5f06"
        },
        {
          "url": "https://git.kernel.org/stable/c/e4feec3174036ba772006be74beee0efa09a9eb8"
        },
        {
          "url": "https://git.kernel.org/stable/c/7d4f5004511757e3984901ffb412fcf858d80ed5"
        },
        {
          "url": "https://git.kernel.org/stable/c/c6376b9b1b4d2bad638256b1b3588e073344ae69"
        },
        {
          "url": "https://git.kernel.org/stable/c/14e4689c113b4c06af1069364ade24fdd7055f33"
        },
        {
          "url": "https://git.kernel.org/stable/c/25918720ba97f974a4f8d433b5a0132c5b43f6f3"
        },
        {
          "url": "https://git.kernel.org/stable/c/19a9493faa4bf3c7bd0a386f30b60b1bb4a3da03"
        },
        {
          "url": "https://git.kernel.org/stable/c/193989cc6d80dd8e0460fb3992e69fa03bf0ff9b"
        }
      ],
      "title": "ipvs: clear the svc scheduler ptr early on edit",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-53270",
    "datePublished": "2026-06-25T08:39:55.830Z",
    "dateReserved": "2026-06-09T07:44:35.395Z",
    "dateUpdated": "2026-08-05T12:34:46.621Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…