๐Ÿ” CVE Alert

CVE-2026-90073

UNKNOWN 0.0

net/sched: hhf: clamp quantum before hhf_change() to avoid overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum before hhf_change() to avoid overflow hhf_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) with no overflow check. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes weight * quantum overflow the signed deficit in hhf_dequeue(), spinning forever. Clamp q->quantum before hhf_change() so both the opt and !opt paths see a sane quantum. Without this, bare "tc qdisc add ... hhf" succeeds with a clamped quantum but "tc qdisc add ... hhf limit 1000" (any option present) fails with -EINVAL because hhf_change() re-validates the unclamped default (sch_hhf.c:559). 256 matches fq_codel's floor and is a sane minimum for a DRR quantum. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
10239edf86f137ce4c39b62ea9575e8053c549a0 < 2e0f0729f922c8de13801004e2131b57646c7c5f 10239edf86f137ce4c39b62ea9575e8053c549a0 < 0c66223e90ddb4fd3700965a9241f2fde7bd6bc7 10239edf86f137ce4c39b62ea9575e8053c549a0 < 20b65bf7ca06e48ec1d62ed8012f71205328dbe4 10239edf86f137ce4c39b62ea9575e8053c549a0 < dea2789a9d5ff38bdd77f2e64d550430899e2839 10239edf86f137ce4c39b62ea9575e8053c549a0 < fa9c2055f0a60f801ccf286af53d387dc6202c3f 10239edf86f137ce4c39b62ea9575e8053c549a0 < 99770b5d8e0e1c69b996f74a19d71afd2c4a9aa4 10239edf86f137ce4c39b62ea9575e8053c549a0 < 2446644b0f6d045b01db6acbaf55552dbec8a59a 10239edf86f137ce4c39b62ea9575e8053c549a0 < 2164b512b97bb053e8ce4d6e95576f11bed6a005
Linux / Linux
3.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2e0f0729f922c8de13801004e2131b57646c7c5f git.kernel.org: https://git.kernel.org/stable/c/0c66223e90ddb4fd3700965a9241f2fde7bd6bc7 git.kernel.org: https://git.kernel.org/stable/c/20b65bf7ca06e48ec1d62ed8012f71205328dbe4 git.kernel.org: https://git.kernel.org/stable/c/dea2789a9d5ff38bdd77f2e64d550430899e2839 git.kernel.org: https://git.kernel.org/stable/c/fa9c2055f0a60f801ccf286af53d387dc6202c3f git.kernel.org: https://git.kernel.org/stable/c/99770b5d8e0e1c69b996f74a19d71afd2c4a9aa4 git.kernel.org: https://git.kernel.org/stable/c/2446644b0f6d045b01db6acbaf55552dbec8a59a git.kernel.org: https://git.kernel.org/stable/c/2164b512b97bb053e8ce4d6e95576f11bed6a005