๐Ÿ” CVE Alert

CVE-2026-90072

UNKNOWN 0.0

net/sched: sfq: clamp quantum to avoid signed overflow soft lockup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: sfq: clamp quantum to avoid signed overflow soft lockup sfq_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) (unsigned). A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, so slot->allot = INT_MIN and INT_MIN + INT_MIN toggles between INT_MIN and 0 forever, spinning sfq_dequeue() under the qdisc lock. Clamp the quantum to [256, 1 << 20] so the refill loop terminates. The lower bound also covers q->quantum == 0 (psched_mtu() returning 0), which spins sfq_dequeue() identically. sfq_change() already rejects a negative quantum, so only the init path was exposed. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 86799499585af06a9431c9e7782658667bd62650 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2017c355a5a1af77736cd1739fe922f69b5652dc 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6581a82bf08ba5d4e2a6d4e3080df43315b296c4 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9d782c662879c3adaaca30e05c36910ad11b9e54 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d72dbdfaeb5b9b8d884e0e036c3442754379ef74 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < aeb8196ecb95146e3410f635628e6cd47352b3e5 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < da16c31517cd2c06bb2c78c73e91ae192c01c426 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 816e90057ab1879562a5b7cc688e35bb9027ae97
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/86799499585af06a9431c9e7782658667bd62650 git.kernel.org: https://git.kernel.org/stable/c/2017c355a5a1af77736cd1739fe922f69b5652dc git.kernel.org: https://git.kernel.org/stable/c/6581a82bf08ba5d4e2a6d4e3080df43315b296c4 git.kernel.org: https://git.kernel.org/stable/c/9d782c662879c3adaaca30e05c36910ad11b9e54 git.kernel.org: https://git.kernel.org/stable/c/d72dbdfaeb5b9b8d884e0e036c3442754379ef74 git.kernel.org: https://git.kernel.org/stable/c/aeb8196ecb95146e3410f635628e6cd47352b3e5 git.kernel.org: https://git.kernel.org/stable/c/da16c31517cd2c06bb2c78c73e91ae192c01c426 git.kernel.org: https://git.kernel.org/stable/c/816e90057ab1879562a5b7cc688e35bb9027ae97