CVE-2026-23105 — Improper Control of a Resource Through its Lifetime in Linux
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateApr 17
Description
In the Linux kernel, the following vulnerability has been resolved:
net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_from_ag
This is more of a preventive patch to make the code more consistent and
to prevent possible exploits that employ child qlen manipulations on qfq.
use cl_is_active instead of relying on the child qdisc's qlen to determine
class activation.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages12 packages
▶CVEListV5linux/linux462dbc9101acd38e92eda93c0726857517a24bbd — fac2c67bb2bb732eae4283e45fc338af7e08c254+7
Patches
🔴Vulnerability Details
2OSV▶
CVE-2026-23105: In the Linux kernel, the following vulnerability has been resolved: net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_fr↗2026-02-04
GHSA▶
GHSA-jvw7-84v9-fr93: In the Linux kernel, the following vulnerability has been resolved:
net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_f↗2026-02-04