{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90076","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.785Z","datePublished":"2026-09-17T16:05:55.517Z","dateUpdated":"2026-09-17T16:05:55.517Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:05:55.517Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fq: add overflow bounds to quantum and initial quantum\n\nfq_init() computes quantum = 2 * psched_mtu() and initial_quantum = 10 *\npsched_mtu() with no overflow check. A device with a huge MTU (e.g. dummy\nwith max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return\n0x80000000; the 2 * and 10 * multiplications wrap to 0 in 32-bit\narithmetic, so q->quantum == 0. Then in fq_dequeue() the credit-refill\nloop adds 0 to f->credit (which stays <= 0) and goto begin loops\nforever under the qdisc lock, creating a soft lockup.\n\nClamp psched_mtu() to [1, 1 << 20] before multiplying so the product\ncannot wrap, then cap the result at 1 << 20, matching the bound already\nenforced on TCA_FQ_QUANTUM in fq_change().\n\nConditions to recreate the bug: a device whose MTU (plus\nhard_header_len) is large enough that 2 * psched_mtu() wraps (e.g. a\ndummy device with max_mtu == 0 accepting MTU 2147483634). Requires\nCAP_NET_ADMIN in a user namespace."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sched/sch_fq.c"],"versions":[{"version":"afe4fd062416b158a8a8538b23adc1930a9b88dc","lessThan":"d16dac3925be95ad46e986d4b139c9898b6e227f","status":"affected","versionType":"git"},{"version":"afe4fd062416b158a8a8538b23adc1930a9b88dc","lessThan":"f6b3e3848a5fca63438984acd6d9eceac80814c1","status":"affected","versionType":"git"},{"version":"afe4fd062416b158a8a8538b23adc1930a9b88dc","lessThan":"e35acd56f244d94355f9ab237c2ecc8fba5e6f04","status":"affected","versionType":"git"},{"version":"afe4fd062416b158a8a8538b23adc1930a9b88dc","lessThan":"709f34f7c28dc4dd6c40343d101850f11e172312","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sched/sch_fq.c"],"versions":[{"version":"3.12","status":"affected"},{"version":"0","lessThan":"3.12","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.12","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.12","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.12","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d16dac3925be95ad46e986d4b139c9898b6e227f"},{"url":"https://git.kernel.org/stable/c/f6b3e3848a5fca63438984acd6d9eceac80814c1"},{"url":"https://git.kernel.org/stable/c/e35acd56f244d94355f9ab237c2ecc8fba5e6f04"},{"url":"https://git.kernel.org/stable/c/709f34f7c28dc4dd6c40343d101850f11e172312"}],"title":"net/sched: fq: add overflow bounds to quantum and initial quantum","x_generator":{"engine":"bippy-1.2.0"}}}}