CVE-2026-98009
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: clamp quantum in parse and fallback paths
ets_qdisc_change() falls back to psched_mtu() with no floor for bands without an explicit quantum. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so a zero psched_mtu on a headerless device makes the deficit-refill loop spin under the qdisc lock.
Move the floor into ets_quantum_parse() so explicitly configured quanta are also clamped to [256, 1<<20], not just the fallback path.
Conditions to recreate the bug: CONFIG_NET_SCH_ETS=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices).
tc qdisc add dev dummy0 root ets bands 3 strict 2 quanta 1 1
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < 99ae477b892e203a37985ebc56f0063e072f7f4b | affected |
| Linux | Linux | dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < 8f80b113dea0bed3c1a31a4224b72775cd9ec52d | affected |
| Linux | Linux | dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < de22c30ec5598aca8797f02082d2ee1358dfa3ff | affected |
| Linux | Linux | dcc68b4d8084e1ac9af0d4022d6b1aff6a139a33 < 1c38487f46b243bfeefec0c0c86023a3904f2214 | affected |
| Linux | Linux | 5.6 | affected |
| Linux | Linux | 0 < 5.6 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/99ae477b892e203a37985ebc56f0063e072f7f4b
- https://git.kernel.org/stable/c/8f80b113dea0bed3c1a31a4224b72775cd9ec52d
- https://git.kernel.org/stable/c/de22c30ec5598aca8797f02082d2ee1358dfa3ff
- https://git.kernel.org/stable/c/1c38487f46b243bfeefec0c0c86023a3904f2214
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.