CVE-2026-98011

Source
https://cve.org/CVERecord?id=CVE-2026-98011
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98011.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98011
Downstream
Published
2026-09-25T10:23:35Z
Modified
2026-09-26T03:48:31Z
Summary
net/sched: hhf: clamp quantum in change and init paths
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sched: hhf: clamp quantum in change and init paths

hhf_change() accepts any quantum from userspace, including 1. With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1 makes the deficit-refill loop spin ~2^31 times under the qdisc lock (a soft lockup / denial of service).

Add max(256U, ...) in hhf_change() matching fq_codel_change(). Clamp hhf_init() to [256, 1<<20] matching the siblings, and remove the old fallback that only set quantum=256 on overflow.

Conditions to recreate the bug: CONFIG_NET_SCH_HHF=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices).

tc qdisc add dev dummy0 root hhf tc qdisc change dev dummy0 root hhf quantum 1 stab data 32768 size_log 15 cell_log 0

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98011.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
10239edf86f137ce4c39b62ea9575e8053c549a0
Fixed
1113b674307ffddd402524bd1fd9d7d5629b705b
Fixed
2e77947bbf6c166e76c038663832d0914418f761
Fixed
0898c6f9fa9ce2632ae88bd0f34a878ccc6335af
Fixed
eb56a495f59baf6cad5ed80e3ffb9078098b1346

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98011.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98011.json"