Back

HIGH

net/sched: fix pedit partial COW leading to page cache corruption

Published Jun 16, 2026

Description

tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd.

Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.

Affected products

Remediation

Red Hat statement

Red Hat rates this flaw as Important severity. This vulnerability is in the kernel's traffic control (tc) pedit action, which requires CAP_NET_ADMIN capability to configure. By default in Red Hat Enterprise Linux, this limits exploitation to the root user or processes explicitly granted network administration capabilities. However, in some circumstances unprivileged users may obtain CAP_NET_ADMIN within user namespaces. Successful exploitation could lead to arbitrary code execution in kernel context or a system crash. Red Hat Enterprise Linux 7 and earlier are not affected. Within OpenShift Container Platform, the vulnerable module is not loaded by default, reducing the severity to Low.

Red Hat mitigation

To mitigate this vulnerability, prevent the 'act_pedit' kernel module from loading. Create a file `/etc/modprobe.d/disable-act_pedit.conf` with the following content: `install act_pedit /bin/true` Then, regenerate the initramfs and reboot the system for the changes to take effect. This may impact network traffic control functionality that relies on the pedit action.

Metrics

References (47)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jun 16, 2026
Updated Sep 15, 2026
Reserved May 13, 2026
CISA Vulnrichment
Updated Jun 29, 2026
NVD
Status Modified
Modified Sep 2, 2026
Red Hat
Severity Important
Public date May 18, 2026