SB20260919165 - Infinite loop in Linux kernel sched
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Infinite loop (CVE-ID: CVE-2026-90053)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an infinite loop in the HTB packet classifier htb_classify() when processing packets with cyclic inner-class filter selections. A local user can configure cyclic HTB filters and send a packet to cause a denial of service.
Exploitation is reachable through an unprivileged user namespace that provides CAP_NET_ADMIN.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/010d05df52cec053bdc67d82c5b61cc4996f3fde
- https://git.kernel.org/stable/c/729c4896ab829169f95915d65edd530325910b37
- https://git.kernel.org/stable/c/83bb11805b620c498d6417e0e409f26887981489
- https://git.kernel.org/stable/c/872317e84fd019ceffba125e62d31586e3336d41
- https://git.kernel.org/stable/c/8c9611f7ba3ea5594e41bac952363aa0966d3280
- https://git.kernel.org/stable/c/90a149ab1f8344b7f713e9a838f69fde9e8d2a51
- https://git.kernel.org/stable/c/e54be9aa503a0297b63aec530fbf760350effd45