{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "a0e947c9ccffe47d45aca793d9e7fe4f4494e381"
            },
            {
              "fixed": "9eaba16f1b6ee19b249e6afd82c27f958d441458"
            },
            {
              "fixed": "1be63e4579af408d596f0f3165faf1a880631d3b"
            },
            {
              "fixed": "57b477e46ef2df3483f3488cc713c61c4b384aab"
            },
            {
              "fixed": "6e05e46fa821a5c1b281355f1f622ac76cb6080a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.8.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98235.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: release tail references on DELACTION failure\n\nA batched RTM_DELACTION request takes a temporary reference on each\naction before attempting any deletion. tcf_action_delete() clears\neach processed slot and drops its temporary reference before attempting\nthe deletion. If deletion fails, tca_action_gd() calls\ntcf_action_put_many() to release the remaining references, but its\ntcf_act_for_each_action() iterator stops at the first NULL slot.\n\nWhen a batch stops at an action bound to a filter, this leaks a\nreference on each subsequent action. A later delete of an unbound\naction can then return success without removing it from the IDR.\n\nWalk the full array in tcf_action_put_many() and skip NULL slots to\nrelease the references held on the unprocessed actions.",
  "id": "CVE-2026-98235",
  "modified": "2026-10-08T02:30:24.097263795Z",
  "published": "2026-10-06T08:45:07.909Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1be63e4579af408d596f0f3165faf1a880631d3b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/57b477e46ef2df3483f3488cc713c61c4b384aab"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/6e05e46fa821a5c1b281355f1f622ac76cb6080a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9eaba16f1b6ee19b249e6afd82c27f958d441458"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98235.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98235"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "net/sched: act_api: release tail references on DELACTION failure"
}