๐Ÿ” CVE Alert

CVE-2026-98010

UNKNOWN 0.0

net/sched: drr: clamp quantum in change class

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: drr: clamp quantum in change class drr_change_class() rejects explicit quantum==0 but falls back to psched_mtu() with no floor. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1 (or a zero psched_mtu on a headerless device) makes the deficit-refill loop spin under the qdisc lock. Add clamp_t(u32, quantum, 256, 1<<20) after the zero reject and on the fallback path. The explicit-zero reject is preserved. Conditions to recreate the bug: CONFIG_NET_SCH_DRR=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices). tc qdisc add dev dummy0 root drr tc class add dev dummy0 parent 1: classid 1:1 drr quantum 1

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
13d2a1d2b032de08d7dcab6a1edcd47802681f96 < dc8b374214ef5bba4882bbd95b361e42555cfc0d 13d2a1d2b032de08d7dcab6a1edcd47802681f96 < d43cded350fe1218493ad3d37a276aff14108ae6 13d2a1d2b032de08d7dcab6a1edcd47802681f96 < 8f756ae1c87414ce9cc21b30e6e4c036d6e9e80b 13d2a1d2b032de08d7dcab6a1edcd47802681f96 < 8382abec0f1568d0a5590d75a3df92f23fcf5196
Linux / Linux
2.6.29

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/dc8b374214ef5bba4882bbd95b361e42555cfc0d git.kernel.org: https://git.kernel.org/stable/c/d43cded350fe1218493ad3d37a276aff14108ae6 git.kernel.org: https://git.kernel.org/stable/c/8f756ae1c87414ce9cc21b30e6e4c036d6e9e80b git.kernel.org: https://git.kernel.org/stable/c/8382abec0f1568d0a5590d75a3df92f23fcf5196