Integer overflow in Linux kernel - CVE-2026-90075
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an integer overflow in the fq_codel queueing discipline initialization when initializing fq_codel on a device whose MTU causes psched_mtu() to wrap into the sign bit. A local privileged user can configure a device with an oversized MTU to cause a denial of service.
Affected software
How to mitigate CVE-2026-90075
External References
- https://git.kernel.org/stable/c/324f86806673ae4a55f66d28db84577f46f615e1
- https://git.kernel.org/stable/c/3782067ec0d485628b6f1f9ede3eeeb4f611fcf2
- https://git.kernel.org/stable/c/397e2b1f71d9f15b8b4e47d24eb620e4dff8878d
- https://git.kernel.org/stable/c/9f499e5827fdb6d7fdb46a7ce731852f6b1a1bb9
- https://git.kernel.org/stable/c/a9a5b2943a00df2ab81a2209f31dd9e87016f120
- https://git.kernel.org/stable/c/d315ee8a07fd1810880227319cf60e6cd925ef22
- https://git.kernel.org/stable/c/d9ebd8f9aa8b2773235889cb903fafd61f2d8585
- https://git.kernel.org/stable/c/dfb4b61db886917244284b18b44b23d2254b82c2