Answer in brief
CVE-2026-90075 records a Unknown severity vulnerability in net/sched: fq_codel: clamp default quantum and mtu. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <d315ee8a07fd1810880227319cf60e6cd925ef22 || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <a9a5b2943a00df2ab81a2209f31dd9e87016f120 || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <3782067ec0d485628b6f1f9ede3eeeb4f611fcf2 || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <397e2b1f71d9f15b8b4e47d24eb620e4dff8878d || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <324f86806673ae4a55f66d28db84577f46f615e1 || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <dfb4b61db886917244284b18b44b23d2254b82c2 || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9 || >=4b549a2ef4bef9965d97cbd992ba67930cd3e0fe <d9ebd8f9aa8b2773235889cb903fafd61f2d8585 | d315ee8a07fd1810880227319cf60e6cd925ef22, a9a5b2943a00df2ab81a2209f31dd9e87016f120, 3782067ec0d485628b6f1f9ede3eeeb4f611fcf2, 397e2b1f71d9f15b8b4e47d24eb620e4dff8878d, 324f86806673ae4a55f66d28db84577f46f615e1, dfb4b61db886917244284b18b44b23d2254b82c2, 9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9, d9ebd8f9aa8b2773235889cb903fafd61f2d8585 |
| Linux/Linuxgeneric | 3.5 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_codel: clamp default quantum and mtu fq_codel_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) without clamping. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, which overflows the signed flow->deficit to INT_MIN in fq_codel_dequeue(), causing an infinite loop and soft lockup. Emulate fq_codel_change() and constrain to [256, FQ_CODEL_QUANTUM_MAX]. The same unclamped psched_mtu() is assigned to q->cparams.mtu a bit below, and fq_codel_change() never updates it. codel_should_drop() tests "*backlog <= params->mtu"; with mtu == 0x80000000 (~2 GiB) and the default 32 MiB memory_limit, the test is always true, so CoDel is silently and completely disabled (no drops, no ECN). Declare a single clamped mtu and assign both q->quantum and q->cparams.mtu from it, which also removes the double psched_mtu() call. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.
Quoted source text, attributed separately from HOL analysis.