CVE-2026-90050
In the Linux kernel, the following vulnerability has been resolved:
net/sched: fq: clamp quantum and initial_quantum in change path
The fq change path accepts TCA_FQ_QUANTUM in [1, INT_MAX] and TCA_FQ_INITIAL_QUANTUM up to INT_MAX, while fq_init() already clamps to [1, 1<<20]. A user can override the init clamp via tc qdisc change, restoring the small-quantum deficit spin that the init clamp prevents.
Narrow iq_range.max to 1<<20 so TCA_FQ_INITIAL_QUANTUM is rejected at parse time. Clamp TCA_FQ_QUANTUM to [256, 1<<20] in fq_change() and fq_init() quantum to [256, 1<<20] for tiny-MTU devices.
Detalles técnicos trazas, registros y código del informe original
Conditions to recreate the bug: CONFIG_NET_SCH_FQ=y. Requires CAP_NET_ADMIN (namespace-local via unshare -Urn suffices). tc qdisc add dev dummy0 root fq tc qdisc change dev dummy0 root fq quantum 1 stab data 32768 size_log 15 cell_log 0
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90050",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "d16dac3925be95ad46e986d4b139c9898b6e227f",
"lessThan": "a27498d34c3f429fb6db3aa609569f8154afa175",
"versionType": "git"
},
{
"status": "affected",
"version": "f6b3e3848a5fca63438984acd6d9eceac80814c1",
"lessThan": "798283cd0fe7ba997f67e5a917f14ab40afa8d9f",
"versionType": "git"
},
{
"status": "affected",
"version": "e35acd56f244d94355f9ab237c2ecc8fba5e6f04",
"lessThan": "72e9387884554f47b03bfd40fb8b2bf52789c68d",
"versionType": "git"
},
{
"status": "affected",
"version": "709f34f7c28dc4dd6c40343d101850f11e172312",
"lessThan": "094cc07f98dfe70a34e2a1923af17fd29b8cf622",
"versionType": "git"
}
],
"programFiles": [
"net/sched/sch_fq.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.3-rc1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.3-rc1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/sched/sch_fq.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:16:53.363",
"references": [
{
"url": "https://git.kernel.org/stable/c/094cc07f98dfe70a34e2a1923af17fd29b8cf622",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/72e9387884554f47b03bfd40fb8b2bf52789c68d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/798283cd0fe7ba997f67e5a917f14ab40afa8d9f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a27498d34c3f429fb6db3aa609569f8154afa175",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fq: clamp quantum and initial_quantum in change path\n\nThe fq change path accepts TCA_FQ_QUANTUM in [1, INT_MAX] and\nTCA_FQ_INITIAL_QUANTUM up to INT_MAX, while fq_init() already clamps to\n[1, 1<<20]. A user can override the init clamp via tc qdisc change,\nrestoring the small-quantum deficit spin that the init clamp prevents.\n\nNarrow iq_range.max to 1<<20 so TCA_FQ_INITIAL_QUANTUM is rejected at\nparse time. Clamp TCA_FQ_QUANTUM to [256, 1<<20] in fq_change() and\nfq_init() quantum to [256, 1<<20] for tiny-MTU devices.\n\nConditions to recreate the bug:\n CONFIG_NET_SCH_FQ=y. Requires CAP_NET_ADMIN (namespace-local via\n unshare -Urn suffices).\n\n tc qdisc add dev dummy0 root fq\n tc qdisc change dev dummy0 root fq quantum 1 stab data 32768 size_log 15 cell_log 0"
}
],
"lastModified": "2026-09-17T17:16:53.363",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}