Bug 2541248 (CVE-2026-98012) - CVE-2026-98012 kernel: net/sched: sfq: clamp quantum in change path
Summary: CVE-2026-98012 kernel: net/sched: sfq: clamp quantum in change path
Keywords:
Status: NEW
Alias: CVE-2026-98012
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:09 UTC by OSIDB Bzimport
Modified: 2026-09-28 19:47 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:09:59 UTC
In the Linux kernel, the following vulnerability has been resolved:

net/sched: sfq: clamp quantum in change path

sfq_change() accepts any non-negative quantum (only rejects
(int)ctl->quantum < 0). With a crafted size table qdisc_pkt_len reaches
~2 GiB, so quantum=1 makes the deficit-refill loop spin ~2^31 times
under the qdisc lock (a soft lockup / denial of service).

Add max(256U, ...) matching fq_codel_change(). Reject quantum > 1<<20
with -EINVAL, matching fq_codel_change() and the init clamp.

Conditions to recreate the bug:
  CONFIG_NET_SCH_SFQ=y. Requires CAP_NET_ADMIN (namespace-local via
  unshare -Urn suffices).

  tc qdisc add dev dummy0 root sfq
  tc qdisc change dev dummy0 root sfq quantum 1 stab data 32768 size_log 15 cell_log 0


Note You need to log in before you can comment on or make changes to this bug.