CVE-2026-23437
published 2026-04-03CVE-2026-23437: In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev during prep of…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.10-1 (forky) | linux 6.19.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb < 581eee0890a8bde44f1fb78ad3e70502a897d583 | 581eee0890a8bde44f1fb78ad3e70502a897d583 |
| linux | linux | >= 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb < 348758ba74e6a348299965b16a97cfb817545cc0 | 348758ba74e6a348299965b16a97cfb817545cc0 |
| linux | linux | >= 4b623f9f0f59652ea71fcb27d60b4c3b65126dbb < 0f9ea7141f365b4f27226898e62220fb98ef8dc6 | 0f9ea7141f365b4f27226898e62220fb98ef8dc6 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.10-1 | 6.19.10-1 |
| linux | linux_kernel | >= 6.13.1 < 6.18.20 | 6.18.20 |
| linux | linux_kernel | >= 6.19 < 6.19.10 | 6.19.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wj8-78x3-52f8: In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev dur
ghsa_unreviewed·2026-04-03
CVE-2026-23437 GHSA-9wj8-78x3-52f8: In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev dur
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
OSV
CVE-2026-23437: In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev durin
osv·2026-04-03
CVE-2026-23437 CVE-2026-23437: In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev durin
In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections. This is not proper, a conversion from a ref to a locked netdev must include a liveness check (a check if the netdev hasn't been unregistered already). Fix the read cases (those under RCU). Writes needs a separate change to protect from creating the hierarchy after flush has already run.
Red Hat
kernel: net: shaper: protect late read accesses to the hierarchy
vendor_redhat·2026-04-03·CVSS 5.5
CVE-2026-23437 [MEDIUM] CWE-825 kernel: net: shaper: protect late read accesses to the hierarchy
kernel: net: shaper: protect late read accesses to the hierarchy
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
A flaw was found in the Linux kernel's `net: shaper` module. This vulnerability arises from a missing liveness check during Netlink opera
Debian
CVE-2026-23437: linux - In the Linux kernel, the following vulnerability has been resolved: net: shaper...
vendor_debian·2026
CVE-2026-23437 [LOW] CVE-2026-23437: linux - In the Linux kernel, the following vulnerability has been resolved: net: shaper...
In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hierarchy We look up a netdev during prep of Netlink ops (pre- callbacks) and take a ref to it. Then later in the body of the callback we take its lock or RCU which are the actual protections. This is not proper, a conversion from a ref to a locked netdev must include a liveness check (a check if the netdev hasn't been unregistered already). Fix the read cases (those under RCU). Writes needs a separate change to protect from creating the hierarchy after flush has already run.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.10-1)
sid: resolved (fixed in 6.19.10-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23437 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23437 CVE-2026-23437 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23437 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
Source : NVD
Published April 3, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Bugzilla
CVE-2026-23437 kernel: net: shaper: protect late read accesses to the hierarchy
bugzilla·2026-04-03·CVSS 5.5
CVE-2026-23437 [MEDIUM] CVE-2026-23437 kernel: net: shaper: protect late read accesses to the hierarchy
CVE-2026-23437 kernel: net: shaper: protect late read accesses to the hierarchy
In the Linux kernel, the following vulnerability has been resolved:
net: shaper: protect late read accesses to the hierarchy
We look up a netdev during prep of Netlink ops (pre- callbacks)
and take a ref to it. Then later in the body of the callback
we take its lock or RCU which are the actual protections.
This is not proper, a conversion from a ref to a locked netdev
must include a liveness check (a check if the netdev hasn't been
unregistered already). Fix the read cases (those under RCU).
Writes needs a separate change to protect from creating the
hierarchy after flush has already run.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026040312-CVE-2026-23437-9787@gregkh/T
2026-04-03
Published