Integer overflow in Linux kernel - CVE-2026-90109
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a 32-bit integer overflow in the gred_enqueue(), bfifo_enqueue(), and plug_enqueue() queue admission functions when calculating queue admission with a backlog exceeding 4 GiB. A local privileged user can attach a qdisc with a queue limit near 4 GiB and enqueue more than 4 GiB of traffic to cause a denial of service.