CVE-2026-90075

Source
https://cve.org/CVERecord?id=CVE-2026-90075
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90075.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90075
Downstream
Published
2026-09-17T16:05:54Z
Modified
2026-09-18T03:48:35Z
Summary
net/sched: fq_codel: clamp default quantum and mtu
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sched: fq_codel: clamp default quantum and mtu

fq_codel_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) without clamping. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, which overflows the signed flow->deficit to INT_MIN in fq_codel_dequeue(), causing an infinite loop and soft lockup. Emulate fq_codel_change() and constrain to [256, FQ_CODEL_QUANTUM_MAX].

The same unclamped psched_mtu() is assigned to q->cparams.mtu a bit below, and fq_codel_change() never updates it. codel_should_drop() tests "*backlog <= params->mtu"; with mtu == 0x80000000 (~2 GiB) and the default 32 MiB memory_limit, the test is always true, so CoDel is silently and completely disabled (no drops, no ECN). Declare a single clamped mtu and assign both q->quantum and q->cparams.mtu from it, which also removes the double psched_mtu() call.

Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90075.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4b549a2ef4bef9965d97cbd992ba67930cd3e0fe
Fixed
d315ee8a07fd1810880227319cf60e6cd925ef22
Fixed
a9a5b2943a00df2ab81a2209f31dd9e87016f120
Fixed
3782067ec0d485628b6f1f9ede3eeeb4f611fcf2
Fixed
397e2b1f71d9f15b8b4e47d24eb620e4dff8878d
Fixed
324f86806673ae4a55f66d28db84577f46f615e1
Fixed
dfb4b61db886917244284b18b44b23d2254b82c2
Fixed
9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9
Fixed
d9ebd8f9aa8b2773235889cb903fafd61f2d8585

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90075.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.5.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90075.json"