Description
In the Linux kernel, the following vulnerability has been resolved:

net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue

gred_enqueue(), bfifo_enqueue() and plug_enqueue() admit a packet when the
current backlog plus the packet length fits within the queue limit:

sch->qstats.backlog + qdisc_pkt_len(skb) <= sch->limit (gred default VQ)
gred_backlog+qdisc_pkt_len(skb) <= q->limit (gred configured VQ)
sch->qstats.backlog + qdisc_pkt_len(skb) <= sch->limit (bfifo)
sch->qstats.backlog + skb->len <= q->limit (plug)

sch->qstats.backlog and q->backlog are u32, and qdisc_pkt_len()/skb->len
are unsigned int, so all sums are computed in 32 bits and wrap at 2^32.
Once the true backlog exceeds 4 GiB the wrapped sum becomes small and
admission keeps succeeding, so the queue grows without bound and the kernel
can be driven to OOM.

Promote the sums to u64 so admission stops once the true backlog exceeds
the limit. The limit is u32, so the bounded queue stays below 2^32 and
the stored u32 backlog never wraps.

The bug can only be reproduced as root (albeit with ridiculous setup):
attach a gred (or bfifo/plug) qdisc with a limit near 4 GiB,
leaving the default VQ unconfigured (for gred), and drive >4 GiB of
queued traffic (e.g. via a size table / stab to inflate qdisc_pkt_len,
or sustained high-rate traffic). The u32 backlog+len sum wraps at 2^32,
admission keeps succeeding, and the queue grows unboundedly to OOM.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unbounded kernel memory consumption
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a 32‑bit buffer overflow in the backlog calculation for the gred, bfifo, and plug queueing disciplines in the Linux kernel. Backlog and packet length are summed in 32‑bit arithmetic; when the true backlog exceeds 4 GiB the wraparound causes the sum to stay small, so packet admission continues indefinitely. As a result the kernel queue grows without bound, eventually exhausting system memory and triggering an out‑of‑memory condition. The weakness is an integer overflow that leads to uncontrolled resource consumption.

Affected Systems

All Linux kernels that implement the gred, bfifo, or plug queueing disciplines are affected. The patch applies to every Linux kernel version that contained the backlog calculation logic, regardless of specific vendor distribution. No vendor or product name is required beyond the general Linux kernel.

Risk and Exploitability

The exploit requires root privileges and a specialized traffic configuration that forces more than 4 GiB of queued traffic. The EPSS score is indicated as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a low probability of real‑world exploitation. Because the conditions are highly restrictive, the available attack vector is essentially local and would likely be used only for testing or denial‑of‑service experiments.

Generated by OpenCVE AI on September 18, 2026 at 22:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains the backlog wrap fix.
  • Configure gred, bfifo, and plug queue limits well below 4 GiB or disable them in environments where high traffic is expected.
  • Monitor kernel memory usage for abnormal growth and set up alerts to detect potential out‑of‑memory conditions.

Generated by OpenCVE AI on September 18, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue gred_enqueue(), bfifo_enqueue() and plug_enqueue() admit a packet when the current backlog plus the packet length fits within the queue limit: sch->qstats.backlog + qdisc_pkt_len(skb) <= sch->limit (gred default VQ) gred_backlog+qdisc_pkt_len(skb) <= q->limit (gred configured VQ) sch->qstats.backlog + qdisc_pkt_len(skb) <= sch->limit (bfifo) sch->qstats.backlog + skb->len <= q->limit (plug) sch->qstats.backlog and q->backlog are u32, and qdisc_pkt_len()/skb->len are unsigned int, so all sums are computed in 32 bits and wrap at 2^32. Once the true backlog exceeds 4 GiB the wrapped sum becomes small and admission keeps succeeding, so the queue grows without bound and the kernel can be driven to OOM. Promote the sums to u64 so admission stops once the true backlog exceeds the limit. The limit is u32, so the bounded queue stays below 2^32 and the stored u32 backlog never wraps. The bug can only be reproduced as root (albeit with ridiculous setup): attach a gred (or bfifo/plug) qdisc with a limit near 4 GiB, leaving the default VQ unconfigured (for gred), and drive >4 GiB of queued traffic (e.g. via a size table / stab to inflate qdisc_pkt_len, or sustained high-rate traffic). The u32 backlog+len sum wraps at 2^32, admission keeps succeeding, and the queue grows unboundedly to OOM.
Title net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:17.465Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:02.873

Modified: 2026-09-17T17:17:02.873

Link: CVE-2026-90109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:45:15Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound