Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: fq_codel: clamp default quantum and mtu

fq_codel_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) without
clamping. A device with a huge MTU (e.g. dummy with max_mtu == 0
accepting MTU 2147483634) makes psched_mtu() return 0x80000000, which
overflows the signed flow->deficit to INT_MIN in fq_codel_dequeue(),
causing an infinite loop and soft lockup. Emulate fq_codel_change()
and constrain to [256, FQ_CODEL_QUANTUM_MAX].

The same unclamped psched_mtu() is assigned to q->cparams.mtu a bit
below, and fq_codel_change() never updates it. codel_should_drop()
tests "*backlog <= params->mtu"; with mtu == 0x80000000 (~2 GiB) and
the default 32 MiB memory_limit, the test is always true, so CoDel is
silently and completely disabled (no drops, no ECN). Declare a single
clamped mtu and assign both q->quantum and q->cparams.mtu from it,
which also removes the double psched_mtu() call.

Conditions to recreate the bug: a device whose MTU (plus
hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy
device with max_mtu == 0 accepting MTU 2147483634). Requires
CAP_NET_ADMIN in a user namespace.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s fq_codel traffic shaper originally set its scheduling quantum directly from the MTU of the attached device without clamping it. When a device such as a dummy interface accepts an abnormally large MTU—on the order of 2 GiB—the calculation overflows the signed deficit counter, causing the dequeue routine to enter an infinite loop. The resulting kernel soft lockup stalls the interface, and because the CoDel algorithm’s drop check always succeeds with the oversized MTU, traffic drops are completely disabled. The effect is a denial of service for all packets traversing the affected queueing discipline.

Affected Systems

Any Linux kernel that includes the legacy fq_codel implementation and has not incorporated the fix that clamps the default quantum and MTU values is affected. The vulnerability is actionable when a network device, especially a dummy interface, is configured with an MTU beyond the normal maximum (e.g., 2 GiB).

Risk and Exploitability

The probability of exploitation in the wild is very low, with an EPSS score of less than 1 % and no listing in CISA’s KEV catalog. Nevertheless, the flaw requires CAP_NET_ADMIN privileges, meaning that a local user with administrative rights or a compromised process could trigger the soft lockup. Once triggered, the kernel becomes unresponsive to traffic on the affected qdisc, and the CoDel mechanism ceases to drop or mark packets, potentially disrupting network flows until the system is rebooted or the configuration is corrected.

Generated by OpenCVE AI on September 20, 2026 at 04:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that clamps fq_codel default quantum and MTU values
  • If an immediate kernel upgrade is not possible, reconfigure or remove dummy network interfaces that use MTU values larger than the typical maximum (e.g., 65535)
  • Restrict CAP_NET_ADMIN privileges to trusted administrators to limit the ability to modify interface MTU values
  • As an additional precaution, consider disabling CoDel on affected interfaces until the fix is applied

Generated by OpenCVE AI on September 20, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680
CWE-704

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_codel: clamp default quantum and mtu fq_codel_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) without clamping. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, which overflows the signed flow->deficit to INT_MIN in fq_codel_dequeue(), causing an infinite loop and soft lockup. Emulate fq_codel_change() and constrain to [256, FQ_CODEL_QUANTUM_MAX]. The same unclamped psched_mtu() is assigned to q->cparams.mtu a bit below, and fq_codel_change() never updates it. codel_should_drop() tests "*backlog <= params->mtu"; with mtu == 0x80000000 (~2 GiB) and the default 32 MiB memory_limit, the test is always true, so CoDel is silently and completely disabled (no drops, no ECN). Declare a single clamped mtu and assign both q->quantum and q->cparams.mtu from it, which also removes the double psched_mtu() call. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.
Title net/sched: fq_codel: clamp default quantum and mtu
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:54.851Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:56.670

Modified: 2026-09-17T17:16:56.670

Link: CVE-2026-90075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow

  • CWE-704

    Incorrect Type Conversion or Cast