PT-2026-98672 · Linux · Linux
CVE-2026-98009
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: clamp quantum in parse and fallback paths
ets qdisc change() falls back to psched mtu() with no floor for bands
without an explicit quantum. With a crafted size table qdisc pkt len
reaches ~2 GiB, so a zero psched mtu on a headerless device makes the
deficit-refill loop spin under the qdisc lock.
Move the floor into ets quantum parse() so explicitly configured quanta
are also clamped to [256, 1<<20], not just the fallback path.
Conditions to recreate the bug:
CONFIG NET SCH ETS=y. Requires CAP NET ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root ets bands 3 strict 2 quanta 1 1
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux