-

CVE-2026-98234

net/sched: hhf: cap hh_flows_limit at change time

In the Linux kernel, the following vulnerability has been resolved:

net/sched: hhf: cap hh_flows_limit at change time

hhf_change() stores TCA_HHF_HH_FLOWS_LIMIT with no upper bound. A huge
hh_flows_limit lets each new heavy-hitter flow pass the
hh_flows_current_cnt check in alloc_new_hh() and forces a fixed-size
kzalloc(GFP_ATOMIC) per flow under spoofed traffic, for unbounded memory
growth.

Bound the attribute with NLA_POLICY_MAX() at 2*HH_FLOWS_CNT (the
hhf_init() default) and report the rejected value via extack. The
deprecated nested parse is kept: legacy tc does not set NLA_F_NESTED on
TCA_OPTIONS. Configs relying on hh_limit above the default were relying
on unbounded, unsafe behaviour and are not supported going forward.

hhf_init() also ran hhf_change() before setting the default
hh_flows_limit, so a user-supplied hh_limit at add time was clobbered
back to 2048. Set the default before hhf_change() so the configured
value sticks.

This is a follow-up to commit eb56a495f59b ("net/sched: hhf: clamp
quantum in change and init paths"), which bounded the quantum of the
same qdisc; the hh_flows_limit bound is the remaining unbounded knob of
that series' scope.

Conditions to recreate the bug: CAP_NET_ADMIN in a user namespace;
tc qdisc change dev X root hhf hh_limit 4294967295 succeeds and the
value is echoed by tc qdisc show, unbounding heavy-hitter flow
allocations; also tc qdisc add dev X root hhf hh_limit 500 stores 2048
instead of 500.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < 7adfd0a42174b85c6bd678858ecd6674f403f336
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < 35fd423a5c5132c6f4321f6c4f0a7b4b90af830c
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < 06d2a101e89063cb0b9b459104db48bdfb0a797d
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < d8e2f1f0263b7c97b222c06070cccf13e0ab7112
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < f3f4a5cb4a6e9b1f1f25d34dfc25f836a1601db4
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < 1731ff1d20489afe4cd01b7d16d37f324746ac54
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < f6547d27ce2093c5627636fb63dd0b7523c466f9
Status affected
Version 10239edf86f137ce4c39b62ea9575e8053c549a0
Version < 2cef2588c995722a901368def30befeef9ae55c6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.14
Status affected
Version 0
Version < 3.14
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.066
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7adfd0a42174b85c6bd678858ecd6674f403f336
https://git.kernel.org/stable/c/35fd423a5c5132c6f4321f6c4f0a7b4b90af830c
https://git.kernel.org/stable/c/06d2a101e89063cb0b9b459104db48bdfb0a797d
https://git.kernel.org/stable/c/d8e2f1f0263b7c97b222c06070cccf13e0ab7112
https://git.kernel.org/stable/c/f3f4a5cb4a6e9b1f1f25d34dfc25f836a1601db4
https://git.kernel.org/stable/c/1731ff1d20489afe4cd01b7d16d37f324746ac54
https://git.kernel.org/stable/c/f6547d27ce2093c5627636fb63dd0b7523c466f9
https://git.kernel.org/stable/c/2cef2588c995722a901368def30befeef9ae55c6