PT-2026-98672 · Linux · Linux

CVE-2026-98009

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: clamp quantum in parse and fallback paths
ets qdisc change() falls back to psched mtu() with no floor for bands without an explicit quantum. With a crafted size table qdisc pkt len reaches ~2 GiB, so a zero psched mtu on a headerless device makes the deficit-refill loop spin under the qdisc lock.
Move the floor into ets quantum parse() so explicitly configured quanta are also clamped to [256, 1<<20], not just the fallback path.
Conditions to recreate the bug: CONFIG NET SCH ETS=y. Requires CAP NET ADMIN (namespace-local via unshare -Urn suffices).
tc qdisc add dev dummy0 root ets bands 3 strict 2 quanta 1 1
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98009

Affected Products

Linux