๐Ÿ” CVE Alert

CVE-2026-90076

UNKNOWN 0.0

net/sched: fq: add overflow bounds to quantum and initial quantum

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: add overflow bounds to quantum and initial quantum fq_init() computes quantum = 2 * psched_mtu() and initial_quantum = 10 * psched_mtu() with no overflow check. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000; the 2 * and 10 * multiplications wrap to 0 in 32-bit arithmetic, so q->quantum == 0. Then in fq_dequeue() the credit-refill loop adds 0 to f->credit (which stays <= 0) and goto begin loops forever under the qdisc lock, creating a soft lockup. Clamp psched_mtu() to [1, 1 << 20] before multiplying so the product cannot wrap, then cap the result at 1 << 20, matching the bound already enforced on TCA_FQ_QUANTUM in fq_change(). Conditions to recreate the bug: a device whose MTU (plus hard_header_len) is large enough that 2 * psched_mtu() wraps (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
afe4fd062416b158a8a8538b23adc1930a9b88dc < d16dac3925be95ad46e986d4b139c9898b6e227f afe4fd062416b158a8a8538b23adc1930a9b88dc < f6b3e3848a5fca63438984acd6d9eceac80814c1 afe4fd062416b158a8a8538b23adc1930a9b88dc < e35acd56f244d94355f9ab237c2ecc8fba5e6f04 afe4fd062416b158a8a8538b23adc1930a9b88dc < 709f34f7c28dc4dd6c40343d101850f11e172312
Linux / Linux
3.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d16dac3925be95ad46e986d4b139c9898b6e227f git.kernel.org: https://git.kernel.org/stable/c/f6b3e3848a5fca63438984acd6d9eceac80814c1 git.kernel.org: https://git.kernel.org/stable/c/e35acd56f244d94355f9ab237c2ecc8fba5e6f04 git.kernel.org: https://git.kernel.org/stable/c/709f34f7c28dc4dd6c40343d101850f11e172312