CVE-2026-90073
Last modified
CVE-2026-90073 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum before hhf_change() to avoid overflow hhf_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) with no overflow check. A device with a huge MTU (e.g.
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum before hhf_change() to avoid overflow hhf_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) with no overflow check. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes weight * quantum overflow the signed deficit in hhf_dequeue(), spinning forever. Clamp q->quantum before hhf_change() so both the opt and !opt paths see a sane quantum. Without this, bare "tc qdisc add ... hhf" succeeds with a clamped quantum but "tc qdisc add ... hhf limit 1000" (any option present) fails with -EINVAL because hhf_change() re-validates the unclamped default (sch_hhf.c:559). 256 matches fq_codel's floor and is a sane minimum for a DRR quantum. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < 2e0f0729f922c8de13801004e2131b57646c7c5f; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < 0c66223e90ddb4fd3700965a9241f2fde7bd6bc7; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < 20b65bf7ca06e48ec1d62ed8012f71205328dbe4; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < dea2789a9d5ff38bdd77f2e64d550430899e2839; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < fa9c2055f0a60f801ccf286af53d387dc6202c3f; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < 99770b5d8e0e1c69b996f74a19d71afd2c4a9aa4; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < 2446644b0f6d045b01db6acbaf55552dbec8a59a; >= 10239edf86f137ce4c39b62ea9575e8053c549a0, < 2164b512b97bb053e8ce4d6e95576f11bed6a005 |
| Linux | Linux | 3.14 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90073?
How severe is CVE-2026-90073?
How do I fix CVE-2026-90073?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90068In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90069In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-9007Improper neutralization of input during web page generation …5.5
- CVE-2026-90070In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90071In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90072In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90074In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90075In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90076In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90077In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90078In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90079In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90073?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
