CVE-2026-98009

Summary

In the Linux kernel, the following vulnerability has been resolved:

net/sched: ets: clamp quantum in parse and fallback paths

ets_qdisc_change() falls back to psched_mtu() with no floor for bands without an explicit quantum. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so a zero psched_mtu on a headerless device makes the deficit-refill loop spin under the qdisc lock.

Move the floor into ets_quantum_parse() so explicitly configured quanta are also clamped to [256, 1<<20], not just the fallback path.

Conditions to recreate the bug: CONFIG_NET_SCH_ETS=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices).

tc qdisc add dev dummy0 root ets bands 3 strict 2 quanta 1 1

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxdcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < 99ae477b892e203a37985ebc56f0063e072f7f4baffected
LinuxLinuxdcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < 8f80b113dea0bed3c1a31a4224b72775cd9ec52daffected
LinuxLinuxdcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < de22c30ec5598aca8797f02082d2ee1358dfa3ffaffected
LinuxLinuxdcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < 1c38487f46b243bfeefec0c0c86023a3904f2214affected
LinuxLinux5.6affected
LinuxLinux0 < 5.6unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References