CVE-2026-74620: net/sched: act_gact, act_police: range check the fallback control action

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026082219-CVE-2026-74620-9726@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_gact, act_police: range check the fallback control action

tcf_action_check_ctrlact() range checks the primary control action:

	if (!opcode)
		ret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0;

TC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it
cannot be set that way. But act_gact and act_police each carry a second,
independent control action supplied by user space that never reaches that
helper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject
TC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned
verbatim from the action.

In particular user space can store TC_ACT_CONSUMED, which is
TC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value
range. That verdict tells every caller the action took ownership of the
skb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and
tcf_qevent_handle() all deliberately skip the free for it. The result is
one leaked sk_buff plus its data buffer per packet traversing the filter,
unbounded, for all traffic on the chain including kernel-generated
packets.

Both are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so
with pval = 1 gact_determ() returns the fallback for every packet.
act_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and
tcf_police_mtu_check() always passes.

TC_ACT_CONSUMED was added by commit 720f22fed81b ("net: sched: refactor
reinsert action"), after both goto-chain guards were written:
commit 9469f375ab09 ("net/sched: act_gact: disallow 'goto chain' on
fallback control action") and
commit c08f5ed5d625 ("net/sched: act_police: disallow 'goto chain' on
fallback control action"). Neither guard was widened when the new
verdict appeared.

Factor the existing range test out of tcf_action_check_ctrlact() as
tcf_action_valid() and apply it to both fallbacks. The helper cannot call
tcf_action_check_ctrlact() directly because that also allocates a
goto_chain, which is exactly what these two sites must not do.

Reproduced on v7.2-rc6: kmemleak reports one leaked 232-byte
skbuff_head_cache object plus its 704-byte data buffer per packet. With
this patch both configurations are rejected with -EINVAL and kmemleak
reports none.

The Linux kernel CVE team has assigned CVE-2026-74620 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 5.15.216 with commit efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4
	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 6.1.183 with commit 725efc2ab4a40affc4e285a2dc4896d103948a6c
	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 6.6.152 with commit 6bcb8839aa2d686964a4154650afc4db91e1c514
	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 6.12.104 with commit 5344e01179baa37547ab29fd7b8614f83faa190c
	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 6.18.45 with commit 92f00f1d4d204a428b38e26fce3baee144b6955d
	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 7.1.9 with commit 2e8df8c9190335475a3b64a159d3efd8cdd1cb73
	Issue introduced in 5.3 with commit 720f22fed81bc6fd1765db7014651b6718887bea and fixed in 7.2 with commit 883b56ae58fe657d8497806c7059646e9ba6dbd0

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74620
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	include/net/act_api.h
	net/sched/act_gact.c
	net/sched/act_police.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4
	https://git.kernel.org/stable/c/725efc2ab4a40affc4e285a2dc4896d103948a6c
	https://git.kernel.org/stable/c/6bcb8839aa2d686964a4154650afc4db91e1c514
	https://git.kernel.org/stable/c/5344e01179baa37547ab29fd7b8614f83faa190c
	https://git.kernel.org/stable/c/92f00f1d4d204a428b38e26fce3baee144b6955d
	https://git.kernel.org/stable/c/2e8df8c9190335475a3b64a159d3efd8cdd1cb73
	https://git.kernel.org/stable/c/883b56ae58fe657d8497806c7059646e9ba6dbd0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.