Impact
The Linux kernel’s fq qdisc calculates quantum and initial_quantum by multiplying the device’s MTU. When the MTU is very large, the multiplication overflows, producing a quantum of zero. This causes the dequeue loop to spin indefinitely under the qdisc lock, resulting in a soft lockup that stalls the system. The vulnerability does not grant new privileges and only leads to loss of availability. The weak point is an unchecked integer multiplication leading to wrap‑around, as identified by CWE‑190.
Affected Systems
All Linux kernel releases containing the fq qdisc before the 2026‑90076 patch are affected. The bug can be triggered on any system that allows creation of a network device (for example a dummy interface) with a very large MTU and where the attacker holds CAP_NET_ADMIN privileges in the active namespace. This includes typical server and workstation kernels. No specific vendor or patch level is listed, so the vulnerability applies to machines running older kernels before the fix was applied.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of being actively exploited in the wild. Attackers would need local or namespace‑level control to configure an oversized MTU, making the risk lower than publicly exposed flaws. Nonetheless, the effect is a complete system denial of service due to the soft lockup, which can have significant operational impact. The severity is moderate to high, and patching is strongly advised to eliminate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA