-

CVE-2026-90076

net/sched: fq: add overflow bounds to quantum and initial quantum

In the Linux kernel, the following vulnerability has been resolved:

net/sched: fq: add overflow bounds to quantum and initial quantum

fq_init() computes quantum = 2 * psched_mtu() and initial_quantum = 10 *
psched_mtu() with no overflow check. A device with a huge MTU (e.g. dummy
with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return
0x80000000; the 2 * and 10 * multiplications wrap to 0 in 32-bit
arithmetic, so q->quantum == 0. Then in fq_dequeue() the credit-refill
loop adds 0 to f->credit (which stays <= 0) and goto begin loops
forever under the qdisc lock, creating a soft lockup.

Clamp psched_mtu() to [1, 1 << 20] before multiplying so the product
cannot wrap, then cap the result at 1 << 20, matching the bound already
enforced on TCA_FQ_QUANTUM in fq_change().

Conditions to recreate the bug: a device whose MTU (plus
hard_header_len) is large enough that 2 * psched_mtu() wraps (e.g. a
dummy device with max_mtu == 0 accepting MTU 2147483634). Requires
CAP_NET_ADMIN in a user namespace.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version afe4fd062416b158a8a8538b23adc1930a9b88dc
Version < d16dac3925be95ad46e986d4b139c9898b6e227f
Status affected
Version afe4fd062416b158a8a8538b23adc1930a9b88dc
Version < f6b3e3848a5fca63438984acd6d9eceac80814c1
Status affected
Version afe4fd062416b158a8a8538b23adc1930a9b88dc
Version < e35acd56f244d94355f9ab237c2ecc8fba5e6f04
Status affected
Version afe4fd062416b158a8a8538b23adc1930a9b88dc
Version < 709f34f7c28dc4dd6c40343d101850f11e172312
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.12
Status affected
Version 0
Version < 3.12
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d16dac3925be95ad46e986d4b139c9898b6e227f
https://git.kernel.org/stable/c/f6b3e3848a5fca63438984acd6d9eceac80814c1
https://git.kernel.org/stable/c/e35acd56f244d94355f9ab237c2ecc8fba5e6f04
https://git.kernel.org/stable/c/709f34f7c28dc4dd6c40343d101850f11e172312