CVE-2026-90074

In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_pie: clamp default quantum to avoid signed overflow fq_pie_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) without clamping. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes psched_mtu() return 0x80000000, which overflows the signed flow->deficit to INT_MIN in fq_pie_qdisc_dequeue(), causing an infinite loop and soft lockup. Emulate fq_pie_policy which is already bounded to [1, 1 << 20]; clamp the default to [256, 1 << 20]. 256 matches fq_codel's floor and is a sane minimum for a DRR quantum. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Sep 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-17 17:16

Updated : 2026-09-17 17:16


NVD link : CVE-2026-90074

Mitre link : CVE-2026-90074

CVE.ORG link : CVE-2026-90074


JSON object : View

Products Affected

No product.

CWE

No CWE.