Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: sfq: clamp quantum to avoid signed overflow soft lockup

sfq_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) (unsigned). A
device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU
2147483634) makes psched_mtu() return 0x80000000, so slot->allot = INT_MIN
and INT_MIN + INT_MIN toggles between INT_MIN and 0 forever, spinning
sfq_dequeue() under the qdisc lock.

Clamp the quantum to [256, 1 << 20] so the refill loop terminates. The
lower bound also covers q->quantum == 0 (psched_mtu() returning 0),
which spins sfq_dequeue() identically. sfq_change() already rejects a
negative quantum, so only the init path was exposed.

Conditions to recreate the bug: a device whose MTU (plus
hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy
device with max_mtu == 0 accepting MTU 2147483634). Requires
CAP_NET_ADMIN in a user namespace.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to kernel soft lockup
Action: Immediate Patch
AI Analysis

Impact

This kernel bug causes an infinite loop in the sfq dequeue logic when the quantum value overflows to the negative extreme. The overflow occurs for devices with an excessively large MTU, causing the quantum to be set to the signed MIN value. Twice adding this MIN value toggles the slot allotment between INT_MIN and zero, spinning the scheduler lock irrecoverably. The result is a soft lockup that consumes CPU resources, effectively rendering the system unusable for affected threads.

Affected Systems

All Linux kernel releases that lack the commit introducing quantum clamping are affected. The issue was identified in the net/sched/ sfq subsystem and applies to the generic Linux kernel regardless of distribution or architecture. No specific vendor versions are listed, implying the flaw exists in any unpatched kernel.

Risk and Exploitability

An attacker with CAP_NET_ADMIN rights inside a user namespace can trigger the condition by creating a dummy interface with a legitimate MTU near the 2GB boundary. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating low public exploitation likelihood. However, local privileged exploitation remains feasible and can lead to a denial of service via sustained CPU lockup. The attack vector is inferred to be local privileged input on a susceptible device.

Generated by OpenCVE AI on September 20, 2026 at 03:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the sfq quantum clamping patch (commit 2017c355a5a1af... or later) and reboot the system.
  • If an immediate kernel update is not possible, disable the sfq qdisc on interfaces that use large MTUs or replace the interface with one that has a standard MTU value.
  • Ensure that dummy or other virtual network devices are created with an MTU below the 2GB threshold and that no interface is configured with a huge MTU that would cause psched_mtu to wrap into the sign bit.

Generated by OpenCVE AI on September 20, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: sfq: clamp quantum to avoid signed overflow soft lockup sfq_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) (unsigned). A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, so slot->allot = INT_MIN and INT_MIN + INT_MIN toggles between INT_MIN and 0 forever, spinning sfq_dequeue() under the qdisc lock. Clamp the quantum to [256, 1 << 20] so the refill loop terminates. The lower bound also covers q->quantum == 0 (psched_mtu() returning 0), which spins sfq_dequeue() identically. sfq_change() already rejects a negative quantum, so only the init path was exposed. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.
Title net/sched: sfq: clamp quantum to avoid signed overflow soft lockup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:52.905Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:56.250

Modified: 2026-09-17T17:16:56.250

Link: CVE-2026-90072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound