net/sched: sch_hfsc: Don't make class passive twice

Summary

CVECVE-2026-74284
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:27 UTC
Updated2026-08-15 06:22:27 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: Don't make class passive twice update_vf() is called from two places for the same class during a single dequeue when the class's child qdisc (e.g. codel/fq_codel) drops its last packets while dequeuing: 1. The child calls qdisc_tree_reduce_backlog(), which, now that the child is empty, invokes hfsc_qlen_notify() -> update_vf(cl, 0, 0) and turns the class passive (cl_nactive is decremented up the hierarchy). 2. hfsc_dequeue() then calls update_vf(cl, qdisc_pkt_len(skb), cur_time) to charge the dequeued bytes. On the second call the class is already passive, but its child qdisc is still empty, so update_vf() arms go_passive again: if (cl->qdisc->q.qlen == 0 && cl->cl_flags & HFSC_FSC) go_passive = 1; The leaf is then skipped by the cl_nactive == 0 check inside the loop, which does not clear go_passive, so the stale go_passive propagates to the parent and decrements its cl_nactive a second time. A parent that still has other active children is driven to cl_nactive == 0 and removed from the vttree, even though those siblings are still backlogged. They are never dequeued again and the qdisc stalls. Fix this by only arming go_passive when the class is actually active, so an already-passive class no longer triggers a second passive transition. The byte accounting (cl->cl_total += len) still runs for every ancestor, so dequeued bytes continue to be counted exactly once.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 72c61ffbeeb8c50f6d4d70c65d3283aa1bac57a7 a425c82ff06cda5165e0de3de8c2a445ec1f863e git Not specified
CNA Linux Linux affected a5efc95a33bd4fcb879250852828cc58c7862970 fc973ecd1a079b9a87c360478542f3a56dea085b git Not specified
CNA Linux Linux affected 0475c85426b18eccdcb7f9fb58d8f8e9c6c58c87 15720cd8fa3fc625146128f89a8e11b0449a20a7 git Not specified
CNA Linux Linux affected 9030a91235ae4845ec71902c3e0cecfc9ed1f2df b2a017bfcf565721918ec7355a373911d2f2a227 git Not specified
CNA Linux Linux affected d06476714d2819b550e0cc39222347e2c8941c9d 9221a594c72a1446137926d4c2aa04e345f798dc git Not specified
CNA Linux Linux affected 51eb3b65544c9efd6a1026889ee5fb5aa62da3bb 66dbb13eeb2fc339f8f548a9076be4c1a94857b0 git Not specified
CNA Linux Linux affected 51eb3b65544c9efd6a1026889ee5fb5aa62da3bb 3a49bbae676fef1ffe548971e6229ae2adeb9d10 git Not specified
CNA Linux Linux affected 51eb3b65544c9efd6a1026889ee5fb5aa62da3bb 90b662ea25f5e83bb3b8ccec5b93ced810b92fb8 git Not specified
CNA Linux Linux affected 9a5fd5c2f4d4afdd5e405083ee53e0789ce76956 git Not specified
CNA Linux Linux affected c1175c4ad01dbc9c979d099861fa90a754f72059 git Not specified
CNA Linux Linux affected 5.10.241 5.10.261 semver Not specified
CNA Linux Linux affected 5.15.190 5.15.212 semver Not specified
CNA Linux Linux affected 6.1.138 6.1.178 semver Not specified
CNA Linux Linux affected 6.6.90 6.6.145 semver Not specified
CNA Linux Linux affected 6.12.28 6.12.97 semver Not specified
CNA Linux Linux affected 5.4.297 5.5 semver Not specified
CNA Linux Linux affected 6.14.6 6.15 semver Not specified
CNA Linux Linux affected 6.15 Not specified
CNA Linux Linux unaffected 6.15 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/fc973ecd1a079b9a87c360478542f3a56dea085b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b2a017bfcf565721918ec7355a373911d2f2a227 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/90b662ea25f5e83bb3b8ccec5b93ced810b92fb8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/15720cd8fa3fc625146128f89a8e11b0449a20a7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a425c82ff06cda5165e0de3de8c2a445ec1f863e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9221a594c72a1446137926d4c2aa04e345f798dc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/66dbb13eeb2fc339f8f548a9076be4c1a94857b0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3a49bbae676fef1ffe548971e6229ae2adeb9d10 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report