SB20260919142 - Integer overflow in Linux kernel sched
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-90074)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to signed integer overflow in the fq_pie queuing discipline when initializing the default quantum from a device MTU. A local privileged user can configure a device with a huge MTU to cause a denial of service.
Exploitation requires CAP_NET_ADMIN in a user namespace and a device whose MTU plus hard header length causes psched_mtu() to wrap into the sign bit.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/044fa2498bbc2900f0c48a6ef2fdd5b2bdfc3795
- https://git.kernel.org/stable/c/1f43e4dbc93b7d02761a024d5f895df823c07b72
- https://git.kernel.org/stable/c/435da3734a8e63d3067016accc977ed1d10aaaa0
- https://git.kernel.org/stable/c/44dad8fe99b58a7fe2961e9eec6a5f07ace5b51f
- https://git.kernel.org/stable/c/6f1be05faecef4c0f9a008200209f66ef2e133f7
- https://git.kernel.org/stable/c/bf97fd2163ad1191ef8daa3d4df8372aee19e396
- https://git.kernel.org/stable/c/c86cd7ed0b0e44779a3d1683f03e4353baf4bdc9
- https://git.kernel.org/stable/c/f7942b2693bc24c7d609a03d06f97bee3b0bd96a