๐Ÿ” CVE Alert

CVE-2026-98011

UNKNOWN 0.0

net/sched: hhf: clamp quantum in change and init paths

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum in change and init paths hhf_change() accepts any quantum from userspace, including 1. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1 makes the deficit-refill loop spin ~2^31 times under the qdisc lock (a soft lockup / denial of service). Add max(256U, ...) in hhf_change() matching fq_codel_change(). Clamp hhf_init() to [256, 1<<20] matching the siblings, and remove the old fallback that only set quantum=256 on overflow. Conditions to recreate the bug: CONFIG_NET_SCH_HHF=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices). tc qdisc add dev dummy0 root hhf tc qdisc change dev dummy0 root hhf quantum 1 stab data 32768 size_log 15 cell_log 0

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
10239edf86f137ce4c39b62ea9575e8053c549a0 < 1113b674307ffddd402524bd1fd9d7d5629b705b 10239edf86f137ce4c39b62ea9575e8053c549a0 < 2e77947bbf6c166e76c038663832d0914418f761 10239edf86f137ce4c39b62ea9575e8053c549a0 < 0898c6f9fa9ce2632ae88bd0f34a878ccc6335af 10239edf86f137ce4c39b62ea9575e8053c549a0 < eb56a495f59baf6cad5ed80e3ffb9078098b1346
Linux / Linux
3.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1113b674307ffddd402524bd1fd9d7d5629b705b git.kernel.org: https://git.kernel.org/stable/c/2e77947bbf6c166e76c038663832d0914418f761 git.kernel.org: https://git.kernel.org/stable/c/0898c6f9fa9ce2632ae88bd0f34a878ccc6335af git.kernel.org: https://git.kernel.org/stable/c/eb56a495f59baf6cad5ed80e3ffb9078098b1346