SB20260919143 - Integer overflow in Linux kernel sched
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-90075)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an integer overflow in the fq_codel queueing discipline initialization when initializing fq_codel on a device whose MTU causes psched_mtu() to wrap into the sign bit. A local privileged user can configure a device with an oversized MTU to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/324f86806673ae4a55f66d28db84577f46f615e1
- https://git.kernel.org/stable/c/3782067ec0d485628b6f1f9ede3eeeb4f611fcf2
- https://git.kernel.org/stable/c/397e2b1f71d9f15b8b4e47d24eb620e4dff8878d
- https://git.kernel.org/stable/c/9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9
- https://git.kernel.org/stable/c/a9a5b2943a00df2ab81a2209f31dd9e87016f120
- https://git.kernel.org/stable/c/d315ee8a07fd1810880227319cf60e6cd925ef22
- https://git.kernel.org/stable/c/d9ebd8f9aa8b2773235889cb903fafd61f2d8585
- https://git.kernel.org/stable/c/dfb4b61db886917244284b18b44b23d2254b82c2