๐Ÿ” CVE Alert

CVE-2026-72036

UNKNOWN 0.0

net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked multiq_dequeue() takes a packet from a band's child with a direct ->dequeue() call after multiq_peek() peeked it. When the child is non-work-conserving the peek stashes the skb in the child's gso_skb, so the direct dequeue returns a different skb and orphans the stash, desyncing the child's qlen/backlog. With a qfq child reached through a peeking parent (e.g. tbf) this re-enters the child on an emptied list and dereferences NULL, panicking the kernel from softirq on ordinary egress. Take the packet through qdisc_dequeue_peeked(), as sch_prio already does and as sch_red and sch_sfb were just fixed to do. The helper is a no-op when the child has no stash, so a work-conserving child is unaffected.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
77be155cba4e163e8bba9fd27222a8b6189ec4f7 < 3e5fd9d14f2d228e7260251f2e4a1d41ba8f705a 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < eb1a9637f0bd84b5db8803af65dfb1f44785406f 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < 7a5a1582710981ef6637de9f074a60a5b1d63222 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < 86a61e46a1919e8abf4d227c204773dabb24068a 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < 1b9cc255e8089606b92b2adf504e334573682821 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < 5889064919a1e5c0a9469c54895000414fc46944 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < fffeb2ab5eeb823d4c2330571a098f63237c9049 77be155cba4e163e8bba9fd27222a8b6189ec4f7 < 54f6b0c843e228d499eb4b6bbb89df68cad9ad5d
Linux / Linux
2.6.29

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3e5fd9d14f2d228e7260251f2e4a1d41ba8f705a git.kernel.org: https://git.kernel.org/stable/c/eb1a9637f0bd84b5db8803af65dfb1f44785406f git.kernel.org: https://git.kernel.org/stable/c/7a5a1582710981ef6637de9f074a60a5b1d63222 git.kernel.org: https://git.kernel.org/stable/c/86a61e46a1919e8abf4d227c204773dabb24068a git.kernel.org: https://git.kernel.org/stable/c/1b9cc255e8089606b92b2adf504e334573682821 git.kernel.org: https://git.kernel.org/stable/c/5889064919a1e5c0a9469c54895000414fc46944 git.kernel.org: https://git.kernel.org/stable/c/fffeb2ab5eeb823d4c2330571a098f63237c9049 git.kernel.org: https://git.kernel.org/stable/c/54f6b0c843e228d499eb4b6bbb89df68cad9ad5d