SB2026081567 - Uncontrolled Recursion in Linux kernel sched
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Uncontrolled Recursion (CVE-ID: CVE-2026-74382)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in cls_bpf_offload_cmd() in the cls_bpf traffic control offload path when processing a filter replace operation and attempting rollback after repeated tc_setup_cb_replace() failures. A local user can trigger repeated rollback failures to cause a denial of service.
The issue can exhaust kernel stack space during rollback handling, and it is not limited to netdevsim.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/10753da2d659dd425a6e620f47f86852d604f67f
- https://git.kernel.org/stable/c/1387f252a242a51bfbb6eace29c8f8db21b457da
- https://git.kernel.org/stable/c/27db54b90bcc7c37867fe664107fa25ea6a116e4
- https://git.kernel.org/stable/c/33373e1f378a501bc51aa73312f74295c84e3101
- https://git.kernel.org/stable/c/3fa6fb5d771c992ebedbfa7331c6bcc6f33f89b7
- https://git.kernel.org/stable/c/4a76953c3ed043797e81529b9395e9ca6f4c7609
- https://git.kernel.org/stable/c/a018f208ab7512380bd4cf670064d48cba00a1b1
- https://git.kernel.org/stable/c/e2d3b7bab3748c811dc5750ce9a8d62bc7f90ed7