๐Ÿ” CVE Alert

CVE-2026-90075

UNKNOWN 0.0

net/sched: fq_codel: clamp default quantum and mtu

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_codel: clamp default quantum and mtu fq_codel_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) without clamping. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, which overflows the signed flow->deficit to INT_MIN in fq_codel_dequeue(), causing an infinite loop and soft lockup. Emulate fq_codel_change() and constrain to [256, FQ_CODEL_QUANTUM_MAX]. The same unclamped psched_mtu() is assigned to q->cparams.mtu a bit below, and fq_codel_change() never updates it. codel_should_drop() tests "*backlog <= params->mtu"; with mtu == 0x80000000 (~2 GiB) and the default 32 MiB memory_limit, the test is always true, so CoDel is silently and completely disabled (no drops, no ECN). Declare a single clamped mtu and assign both q->quantum and q->cparams.mtu from it, which also removes the double psched_mtu() call. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < d315ee8a07fd1810880227319cf60e6cd925ef22 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < a9a5b2943a00df2ab81a2209f31dd9e87016f120 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < 3782067ec0d485628b6f1f9ede3eeeb4f611fcf2 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < 397e2b1f71d9f15b8b4e47d24eb620e4dff8878d 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < 324f86806673ae4a55f66d28db84577f46f615e1 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < dfb4b61db886917244284b18b44b23d2254b82c2 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < 9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9 4b549a2ef4bef9965d97cbd992ba67930cd3e0fe < d9ebd8f9aa8b2773235889cb903fafd61f2d8585
Linux / Linux
3.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d315ee8a07fd1810880227319cf60e6cd925ef22 git.kernel.org: https://git.kernel.org/stable/c/a9a5b2943a00df2ab81a2209f31dd9e87016f120 git.kernel.org: https://git.kernel.org/stable/c/3782067ec0d485628b6f1f9ede3eeeb4f611fcf2 git.kernel.org: https://git.kernel.org/stable/c/397e2b1f71d9f15b8b4e47d24eb620e4dff8878d git.kernel.org: https://git.kernel.org/stable/c/324f86806673ae4a55f66d28db84577f46f615e1 git.kernel.org: https://git.kernel.org/stable/c/dfb4b61db886917244284b18b44b23d2254b82c2 git.kernel.org: https://git.kernel.org/stable/c/9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9 git.kernel.org: https://git.kernel.org/stable/c/d9ebd8f9aa8b2773235889cb903fafd61f2d8585