Integer overflow in Linux kernel - CVE-2026-90072
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in sfq_init() of the SFQ queueing discipline when initializing SFQ on a device with an MTU that wraps psched_mtu() into the sign bit. A local user can configure a device with a crafted MTU value to cause a denial of service.
Exploitation requires CAP_NET_ADMIN in a user namespace.
Affected software
How to mitigate CVE-2026-90072
External References
- https://git.kernel.org/stable/c/2017c355a5a1af77736cd1739fe922f69b5652dc
- https://git.kernel.org/stable/c/6581a82bf08ba5d4e2a6d4e3080df43315b296c4
- https://git.kernel.org/stable/c/816e90057ab1879562a5b7cc688e35bb9027ae97
- https://git.kernel.org/stable/c/86799499585af06a9431c9e7782658667bd62650
- https://git.kernel.org/stable/c/9d782c662879c3adaaca30e05c36910ad11b9e54
- https://git.kernel.org/stable/c/aeb8196ecb95146e3410f635628e6cd47352b3e5
- https://git.kernel.org/stable/c/d72dbdfaeb5b9b8d884e0e036c3442754379ef74
- https://git.kernel.org/stable/c/da16c31517cd2c06bb2c78c73e91ae192c01c426