-

CVE-2026-98022

net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations

In the Linux kernel, the following vulnerability has been resolved:

net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations

Several subsystems allocate ring buffers sized by dev->tx_queue_len
with no upper bound. An unprivileged user (via unshare -Urn) can set a
huge tx_queue_len and exhaust global memory with ring allocations:

- pfifo_fast: pfifo_fast_init() and pfifo_fast_change_tx_queue_len()
  allocate 3 skb_array rings of tx_queue_len entries each.
- tun: tun_queue_resize() and the queue-attach path resize ptr_rings
  to tx_queue_len on the NETDEV_CHANGE_TX_QUEUE_LEN notifier.
- tap (macvtap/ipvtap): tap_queue_resize() and tap_init() resize/init
  ptr_rings to tx_queue_len on the same notifier.

netif_change_tx_queue_len() is the single entry point for IFLA_TXQLEN,
sysfs, and the SIOCSIFTXQLEN ioctl. Cap new_len at S16_MAX (32767)
there so the oversized value is rejected at set time. This takes
effect whether the device is up or down, before dev->tx_queue_len is
written, before any notifier fires, and before any ring is allocated.
The "> S16_MAX" check also subsumes the previous unsigned-long
truncation test, and a negative ifr_qlen from the ioctl lands far
above the cap after conversion, so both old failure modes are covered
by the one comparison.

tx_queue_len is ambigious: both a per-ring sizing multiplier and a
default queue-length/limit knob for consumers that allocate
nothing at set time (pfifo/bfifo/gred/plug/sfb limits, htb
direct_qlen, qfq max_classes, teql). 32767 is chosen as the largest
value NLA_POLICY_FULL_RANGE can express for the u32 IFLA_TXQLEN
policy in patch 2/3 while staying a legitimate queue length on
high-BDP paths; the ring-memory trade-off of a shared knob is
disclosed below.

Conditions to recreate the bug:
- CONFIG_NET_SCHED=y, CONFIG_VETH=y, CONFIG_USER_NS=y, CONFIG_NET_NS=y.
- Unprivileged user in a fresh user+net namespace (unshare -Urn).
- pfifo_fast: create veth pairs, set tx_queue_len to 500000, attach
  mq+pfifo_fast. ~28 iterations OOMs a 2GB guest.
- tun: create 50 tun devices with IFF_MULTI_QUEUE, set tx_queue_len to
  500000, open 8 queues each. ~1.6GB of ptr_ring allocations OOMs a
  512MB guest.
- tap: same as tun with IFF_TAP. ~960MB OOMs a 512MB guest.
- On the fixed kernel the oversized tx_queue_len is rejected with
  -ERANGE at set time (all four paths: RTM_SETLINK, RTM_NEWLINK
  create, sysfs, ioctl - the latter two via this check, the former
  two via this check and the 2/3 parse policy respectively).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < 24d02c909a1725ab9eceb92db7d02e4e841f17ca
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < 5e5591a0f33f7c11bf1d338dbb6c5072575de64c
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < c8d4060610c69645733c92d94fceb4b93808ac4d
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < c2362c500931e5bd1826bce34e9ce28af80e7541
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < 81c0e02076989743a603806a5a4f44d2c40dc01f
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < 081340cf70a789b94b4174af54a63ffd49677a4e
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < a03b927bae4af5c23fd5315a237855c17cc8f422
Status affected
Version 6a643ddb5624be7e0694d49f5765a8d41c1ab6d0
Version < 66ab4c59b74db7ab53a1c9083feaaede393a96a0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.16
Status affected
Version 0
Version < 4.16
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/81c0e02076989743a603806a5a4f44d2c40dc01f
https://git.kernel.org/stable/c/081340cf70a789b94b4174af54a63ffd49677a4e
https://git.kernel.org/stable/c/a03b927bae4af5c23fd5315a237855c17cc8f422
https://git.kernel.org/stable/c/66ab4c59b74db7ab53a1c9083feaaede393a96a0
https://git.kernel.org/stable/c/24d02c909a1725ab9eceb92db7d02e4e841f17ca
https://git.kernel.org/stable/c/5e5591a0f33f7c11bf1d338dbb6c5072575de64c
https://git.kernel.org/stable/c/c2362c500931e5bd1826bce34e9ce28af80e7541
https://git.kernel.org/stable/c/c8d4060610c69645733c92d94fceb4b93808ac4d