net/sched: netem: fix queue limit check to include reordered packets

Summary

CVECVE-2026-52984
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-24 17:17:09 UTC
Updated2026-06-24 17:17:09 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net/sched: netem: fix queue limit check to include reordered packets The queue limit check in netem_enqueue() uses q->t_len which only counts packets in the internal tfifo. Packets placed in sch->q by the reorder path (__qdisc_enqueue_head) are not counted, allowing the total queue occupancy to exceed sch->limit under reordering. Include sch->q.qlen in the limit check.

Risk And Classification

EPSS: 0.001840000 probability, percentile 0.081880000 (date 2026-06-29)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 216509dda290f6db92c816dd54b83c1df9da9e76 0f875d52db4c921da610e481b72f03cc82fdcb72 git Not specified
CNA Linux Linux affected c2047b0e216c8edce227d7c42f99ac2877dad0e4 ef9a41b3870fb90577da5b2de5bd140022d4021e git Not specified
CNA Linux Linux affected 10df49cfca73dfbbdb6c4150d859f7e8926ae427 74fcd8e127200a50ee22ba2b45c164722bdb9177 git Not specified
CNA Linux Linux affected 3824c5fad18eeb7abe0c4fc966f29959552dca3e 39a66e83ea41fe845631eeb8d326953de27d13f9 git Not specified
CNA Linux Linux affected 356078a5c55ec8d2061fcc009fb8599f5b0527f9 54b5dbacd00dedffd5e2eed76de1c3839996b5e6 git Not specified
CNA Linux Linux affected f8d4bc455047cf3903cd6f85f49978987dbb3027 8450462eaf91d5d2a9e863507b16d18e814baef3 git Not specified
CNA Linux Linux affected f8d4bc455047cf3903cd6f85f49978987dbb3027 936a7dd87251f6f3e88983350833edf60fe6a80b git Not specified
CNA Linux Linux affected f8d4bc455047cf3903cd6f85f49978987dbb3027 4185701fcce6b426b6c3630b25330dddd9c47b0d git Not specified
CNA Linux Linux affected 83c6ab12f08dcc09d4c5ac86fdb89736b28f1d31 git Not specified
CNA Linux Linux affected 5.10.232 5.10.258 semver Not specified
CNA Linux Linux affected 5.15.175 5.15.209 semver Not specified
CNA Linux Linux affected 6.1.121 6.1.175 semver Not specified
CNA Linux Linux affected 6.6.67 6.6.141 semver Not specified
CNA Linux Linux affected 6.12.6 6.12.91 semver Not specified
CNA Linux Linux affected 5.4.288 5.5 semver Not specified
CNA Linux Linux affected 6.13 Not specified
CNA Linux Linux unaffected 6.13 semver Not specified
CNA Linux Linux unaffected 5.10.258 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.141 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.91 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.33 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.10 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0f875d52db4c921da610e481b72f03cc82fdcb72 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/936a7dd87251f6f3e88983350833edf60fe6a80b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8450462eaf91d5d2a9e863507b16d18e814baef3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4185701fcce6b426b6c3630b25330dddd9c47b0d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/39a66e83ea41fe845631eeb8d326953de27d13f9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/74fcd8e127200a50ee22ba2b45c164722bdb9177 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/54b5dbacd00dedffd5e2eed76de1c3839996b5e6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ef9a41b3870fb90577da5b2de5bd140022d4021e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report