PT-2026-94406 · Linux · Linux Kernel

CVE-2026-90058

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the network scheduler where the qdisc get stab() function accepts a user-supplied size table. The qdisc calculate pkt len() function can amplify the qdisc pkt len() value through overhead, size-table data, and size log. A specially crafted size table can set qdisc pkt len() to approximately 1 GiB for a standard socket buffer (skb). Per-flow deficit schedulers, such as DRR and ETS, replenish one quantum per loop iteration; if a tiny quantum of 1 is used, the system may spin billions of times under the qdisc lock, resulting in a soft lockup or RCU stall. This is reachable by root or an unprivileged user in a new user and network namespace with CAP NET ADMIN privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102933
CVE-2026-90058
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel