VDB

CVE-2026-53270

CVE-2026-53270 PUBLISHED CVSS 7.8 HIGH

Reported by Linux · Published June 25, 2026

In the Linux kernel, the following vulnerability has been resolved: ipvs: clear the svc scheduler ptr early on edit ip_vs_edit_service() while unbinding the old scheduler clears the svc->scheduler ptr after the scheduler module initiates RCU callbacks. This can cause packets to use the old scheduler at the time when svc->sched_data is already freed after RCU grace period. Fix it by clearing the ptr early in ip_vs_unbind_scheduler(), before the done_service method schedules any RCU callbacks. Also, if the new scheduler fails to initialize when replacing the old scheduler, try to restore the old scheduler while still returning the error code.

EPSS 0.17% · 6.9th percentile

Risk Scores

CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.17%
6.9th percentile

Affected Products

VendorProductVersions
LinuxLinux05f00505a89acd21f5d0d20f5797dfbc4cf85243, 05f00505a89acd21f5d0d20f5797dfbc4cf85243, 05f00505a89acd21f5d0d20f5797dfbc4cf85243
LinuxLinux4.2, 0, 5.10.259
linuxlinux_kernel4.2, 4.2, 4.2
LinuxLinux05f00505a89acd21f5d0d20f5797dfbc4cf85243, 05f00505a89acd21f5d0d20f5797dfbc4cf85243, 05f00505a89acd21f5d0d20f5797dfbc4cf85243

Timeline

  • Jun 25, 2026 CVE Published
  • Jun 26, 2026 EPSS Score
  • Jun 26, 2026 Coalition ESS Score
  • Jun 28, 2026 CVE Updated
  • Jun 29, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›