Incomplete cleanup in Linux kernel - CVE-2026-97966

 

Incomplete cleanup in Linux kernel - CVE-2026-97966

Published: September 28, 2026


Vulnerability identifier: #VU152505
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97966
CWE-ID: CWE-459
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to affect scheduler topology settings for later queue allocations.

The vulnerability exists due to incomplete cleanup of scheduler topology state in the OcteonTX2 PF QoS scheduler queue teardown logic when freeing QoS-allocated scheduler queues. A local user can trigger QoS scheduler hierarchy teardown to affect scheduler topology settings for later queue allocations.

PRIO_ANCHOR and RR_PRIO settings can persist in the shared scheduler pool.


Affected software

Linux kernel

How to mitigate CVE-2026-97966

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins