Improper control of a resource through its lifetime in Linux kernel - CVE-2026-80630
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the sch_fq_codel queueing discipline when peeking queued packets after packet drops. A local user can trigger packet drops during peek to cause a denial of service.
The issue can incorrectly invoke the parent qlen_notify callback while a packet still remains queued, which may mistakenly deactivate the parent class and lead to wild memory access in sch_qfq.
Affected software
How to mitigate CVE-2026-80630
External References
- https://git.kernel.org/stable/c/0500af8630c3253f0dde879bd3a73a06bb2f2b3f
- https://git.kernel.org/stable/c/097f6fc7b1ae362dd7a9444b2572162fda73b284
- https://git.kernel.org/stable/c/20dd591d8f951e1e6aca5052be8785e6181055e2
- https://git.kernel.org/stable/c/3e515188393e62a718ccebee651ee74514104ff6
- https://git.kernel.org/stable/c/7c09843fd2b44d9bf0de798683861d1aecd62a08
- https://git.kernel.org/stable/c/94a5f1efdefb01f82cd228bf4e7ef1e8fc075c80
- https://git.kernel.org/stable/c/acc08a0c7f37ebb1901144e03a7cba7d4afd9203
- https://git.kernel.org/stable/c/af54df2f44d9605614bc7ed96640302a240a9a62