Integer overflow in Linux kernel - CVE-2026-90074
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to signed integer overflow in the fq_pie queuing discipline when initializing the default quantum from a device MTU. A local privileged user can configure a device with a huge MTU to cause a denial of service.
Exploitation requires CAP_NET_ADMIN in a user namespace and a device whose MTU plus hard header length causes psched_mtu() to wrap into the sign bit.
Affected software
How to mitigate CVE-2026-90074
External References
- https://git.kernel.org/stable/c/044fa2498bbc2900f0c48a6ef2fdd5b2bdfc3795
- https://git.kernel.org/stable/c/1f43e4dbc93b7d02761a024d5f895df823c07b72
- https://git.kernel.org/stable/c/435da3734a8e63d3067016accc977ed1d10aaaa0
- https://git.kernel.org/stable/c/44dad8fe99b58a7fe2961e9eec6a5f07ace5b51f
- https://git.kernel.org/stable/c/6f1be05faecef4c0f9a008200209f66ef2e133f7
- https://git.kernel.org/stable/c/bf97fd2163ad1191ef8daa3d4df8372aee19e396
- https://git.kernel.org/stable/c/c86cd7ed0b0e44779a3d1683f03e4353baf4bdc9
- https://git.kernel.org/stable/c/f7942b2693bc24c7d609a03d06f97bee3b0bd96a