Answer in brief
CVE-2026-98012 records a Unknown severity vulnerability in net/sched: sfq: clamp quantum in change path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=82bd38bd5467ece1ee274b493f51326cf5220a5a <f3820dce042a673fcb28cc31c87ee14257e21a17 || >=e4650d7ae4252f67e997a632adfae0dd74d3a99a <534cd7ecbbc6e8a974f4003a5c1557439c6e0a72 || >=e4650d7ae4252f67e997a632adfae0dd74d3a99a <e6c1cb728e389354203a72bc77464c222a247aeb || >=e4650d7ae4252f67e997a632adfae0dd74d3a99a <fb9f88a33c516ea5c0bcd9a22ca288b246b34567 || 843cacb88f42f426973f1ed11c6fb562558efb27 || 4919649699c5f4dbae08b8e2ed536fc9d6c3c2aa || 548cf048b426729a7a1fa6acd1271c010c9a7380 || c49ac48fac51a6a54efd5963954d02bacf075085 || 58ae7465f0e7113d45aa88a66bf2d203c71c195e || >=6.12.13 <6.12.111 || >=5.4.297 <5.5 || >=5.10.239 <5.11 || >=5.15.186 <5.16 || >=6.1.129 <6.2 || >=6.6.76 <6.7 | f3820dce042a673fcb28cc31c87ee14257e21a17, 534cd7ecbbc6e8a974f4003a5c1557439c6e0a72, e6c1cb728e389354203a72bc77464c222a247aeb, fb9f88a33c516ea5c0bcd9a22ca288b246b34567, 6.12.111, 5.5, 5.11, 5.16, 6.2, 6.7 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sched: sfq: clamp quantum in change path sfq_change() accepts any non-negative quantum (only rejects (int)ctl->quantum < 0). With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1 makes the deficit-refill loop spin ~2^31 times under the qdisc lock (a soft lockup / denial of service). Add max(256U, ...) matching fq_codel_change(). Reject quantum > 1<<20 with -EINVAL, matching fq_codel_change() and the init clamp. Conditions to recreate the bug: CONFIG_NET_SCH_SFQ=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices). tc qdisc add dev dummy0 root sfq tc qdisc change dev dummy0 root sfq quantum 1 stab data 32768 size_log 15 cell_log 0
Quoted source text, attributed separately from HOL analysis.