Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: fq: add overflow bounds to quantum and initial quantum

fq_init() computes quantum = 2 * psched_mtu() and initial_quantum = 10 *
psched_mtu() with no overflow check. A device with a huge MTU (e.g. dummy
with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return
0x80000000; the 2 * and 10 * multiplications wrap to 0 in 32-bit
arithmetic, so q->quantum == 0. Then in fq_dequeue() the credit-refill
loop adds 0 to f->credit (which stays <= 0) and goto begin loops
forever under the qdisc lock, creating a soft lockup.

Clamp psched_mtu() to [1, 1 << 20] before multiplying so the product
cannot wrap, then cap the result at 1 << 20, matching the bound already
enforced on TCA_FQ_QUANTUM in fq_change().

Conditions to recreate the bug: a device whose MTU (plus
hard_header_len) is large enough that 2 * psched_mtu() wraps (e.g. a
dummy device with max_mtu == 0 accepting MTU 2147483634). Requires
CAP_NET_ADMIN in a user namespace.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via integer overflow
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s fq qdisc calculates quantum and initial_quantum by multiplying the device’s MTU. When the MTU is very large, the multiplication overflows, producing a quantum of zero. This causes the dequeue loop to spin indefinitely under the qdisc lock, resulting in a soft lockup that stalls the system. The vulnerability does not grant new privileges and only leads to loss of availability. The weak point is an unchecked integer multiplication leading to wrap‑around, as identified by CWE‑190.

Affected Systems

All Linux kernel releases containing the fq qdisc before the 2026‑90076 patch are affected. The bug can be triggered on any system that allows creation of a network device (for example a dummy interface) with a very large MTU and where the attacker holds CAP_NET_ADMIN privileges in the active namespace. This includes typical server and workstation kernels. No specific vendor or patch level is listed, so the vulnerability applies to machines running older kernels before the fix was applied.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of being actively exploited in the wild. Attackers would need local or namespace‑level control to configure an oversized MTU, making the risk lower than publicly exposed flaws. Nonetheless, the effect is a complete system denial of service due to the soft lockup, which can have significant operational impact. The severity is moderate to high, and patching is strongly advised to eliminate the risk.

Generated by OpenCVE AI on September 20, 2026 at 03:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fq qdisc patch fixing integer overflow in quantum calculations.
  • Remove or reconfigure any dummy or user‑created network interfaces that can have an MTU set above the normal range, and ensure interface MTUs are capped at a safe maximum (e.g., 9216 or 1 << 20 bytes).
  • Restrict CAP_NET_ADMIN privileges for untrusted processes in user namespaces to prevent malicious MTU manipulation until the kernel is updated.

Generated by OpenCVE AI on September 20, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: add overflow bounds to quantum and initial quantum fq_init() computes quantum = 2 * psched_mtu() and initial_quantum = 10 * psched_mtu() with no overflow check. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000; the 2 * and 10 * multiplications wrap to 0 in 32-bit arithmetic, so q->quantum == 0. Then in fq_dequeue() the credit-refill loop adds 0 to f->credit (which stays <= 0) and goto begin loops forever under the qdisc lock, creating a soft lockup. Clamp psched_mtu() to [1, 1 << 20] before multiplying so the product cannot wrap, then cap the result at 1 << 20, matching the bound already enforced on TCA_FQ_QUANTUM in fq_change(). Conditions to recreate the bug: a device whose MTU (plus hard_header_len) is large enough that 2 * psched_mtu() wraps (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.
Title net/sched: fq: add overflow bounds to quantum and initial quantum
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:55.517Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:56.820

Modified: 2026-09-17T17:16:56.820

Link: CVE-2026-90076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound