Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90058
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of user-supplied size table values in __qdisc_calculate_pkt_len() when processing a crafted TCA_STAB configuration that amplifies packet length values. A local user can configure a DRR or ETS qdisc with a crafted size table, set a tiny quantum, and send a small packet to cause a denial of service.
The issue requires NET_SCHED and either the DRR or ETS scheduler to be enabled.
Affected software
How to mitigate CVE-2026-90058
External References
- https://git.kernel.org/stable/c/0bc5a6280a132a2170c6fa742436e01b635f02de
- https://git.kernel.org/stable/c/16d21a27df3f50b7251c9388fc5a7ab22703b469
- https://git.kernel.org/stable/c/1a5c26e586481bc82abc19ac92c3d9f10518f525
- https://git.kernel.org/stable/c/448c34421b38ec7c93a0060a885218ca319d382b
- https://git.kernel.org/stable/c/4f0f4b09a95ef602fbdae948326beadd9c20eab3
- https://git.kernel.org/stable/c/6e78792d8ce1fa3561713860ee8086901dde4f99
- https://git.kernel.org/stable/c/82fdbf49b9f7528c82bf608cfa9710e5f81a198c
- https://git.kernel.org/stable/c/8f735d64382dcf162f4276d6699d03ad2f859c0b