net/sched: hhf: clamp quantum before hhf_change() to avoid overflow

Summary

CVECVE-2026-90073
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:16:56 UTC
Updated2026-09-17 17:16:56 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum before hhf_change() to avoid overflow hhf_init() sets q->quantum = psched_mtu(qdisc_dev(sch)) with no overflow check. A device with a huge MTU (e.g. dummy with max_mtu == 0 accepting MTU 2147483634) makes weight * quantum overflow the signed deficit in hhf_dequeue(), spinning forever. Clamp q->quantum before hhf_change() so both the opt and !opt paths see a sane quantum. Without this, bare "tc qdisc add ... hhf" succeeds with a clamped quantum but "tc qdisc add ... hhf limit 1000" (any option present) fails with -EINVAL because hhf_change() re-validates the unclamped default (sch_hhf.c:559). 256 matches fq_codel's floor and is a sane minimum for a DRR quantum. Conditions to recreate the bug: a device whose MTU (plus hard_header_len) wraps psched_mtu() into the sign bit (e.g. a dummy device with max_mtu == 0 accepting MTU 2147483634). Requires CAP_NET_ADMIN in a user namespace.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 2e0f0729f922c8de13801004e2131b57646c7c5f git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 0c66223e90ddb4fd3700965a9241f2fde7bd6bc7 git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 20b65bf7ca06e48ec1d62ed8012f71205328dbe4 git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 dea2789a9d5ff38bdd77f2e64d550430899e2839 git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 fa9c2055f0a60f801ccf286af53d387dc6202c3f git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 99770b5d8e0e1c69b996f74a19d71afd2c4a9aa4 git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 2446644b0f6d045b01db6acbaf55552dbec8a59a git Not specified
CNA Linux Linux affected 10239edf86f137ce4c39b62ea9575e8053c549a0 2164b512b97bb053e8ce4d6e95576f11bed6a005 git Not specified
CNA Linux Linux affected 3.14 Not specified
CNA Linux Linux unaffected 3.14 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/99770b5d8e0e1c69b996f74a19d71afd2c4a9aa4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/20b65bf7ca06e48ec1d62ed8012f71205328dbe4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0c66223e90ddb4fd3700965a9241f2fde7bd6bc7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fa9c2055f0a60f801ccf286af53d387dc6202c3f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dea2789a9d5ff38bdd77f2e64d550430899e2839 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2446644b0f6d045b01db6acbaf55552dbec8a59a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2e0f0729f922c8de13801004e2131b57646c7c5f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2164b512b97bb053e8ce4d6e95576f11bed6a005 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report