Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-97616
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service by exhausting action IDs.
The vulnerability exists due to improper resource release in tcf_action_destroy() in net/sched/act_api.c when processing a batched RTM_NEWACTION request that replaces an existing action and a later action fails to initialize. A local user can submit a crafted batched RTM_NEWACTION request to cause a denial of service by exhausting action IDs.