Improper input validation in Linux kernel - CVE-2026-98012
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the SFQ qdisc change path when processing crafted qdisc configuration. A local user can configure a quantum value of 1 with a crafted size table to cause a denial of service.
The SFQ scheduler must be enabled, and exploitation requires CAP_NET_ADMIN, which can be namespace-local.