{"api_version":"1","generated_at":"2026-07-23T12:13:55+00:00","cve":"CVE-2026-64207","urls":{"html":"https://cve.report/CVE-2026-64207","api":"https://cve.report/api/cve/CVE-2026-64207.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64207","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64207"},"summary":{"title":"net/sched: dualpi2: fix GSO backlog accounting","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: dualpi2: fix GSO backlog accounting\n\nWhen DualPI2 splits a GSO skb into N segments, it propagates N\nadditional packets to its parent before returning NET_XMIT_SUCCESS.\nThe parent then accounts for the original skb once more, leaving its\nqlen one larger than the number of packets actually queued.\n\nWith QFQ as the parent, after all real packets are dequeued, QFQ still\nhas a non-zero qlen while its in-service aggregate has no active\nclasses. qfq_choose_next_agg() returns NULL and qfq_dequeue() passes\nthe result to qfq_peek_skb(), causing a NULL pointer dereference.\n\nFollow the same pattern used by tbf_segment() and taprio: count only\nsuccessfully queued segments, propagate the difference between the\noriginal skb and those segments, and return NET_XMIT_SUCCESS whenever\nat least one segment was queued.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-20 17:18:22","updated_at":"2026-07-20 17:18:22"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/806586e33891066487db1f002be3d455cda6b516","name":"https://git.kernel.org/stable/c/806586e33891066487db1f002be3d455cda6b516","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c4b70c1512b8f9f33f23c2c8196dfd1210207681","name":"https://git.kernel.org/stable/c/c4b70c1512b8f9f33f23c2c8196dfd1210207681","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/05ed733b65ab977dd931e7f7ac0f62fdb81205c2","name":"https://git.kernel.org/stable/c/05ed733b65ab977dd931e7f7ac0f62fdb81205c2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64207","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64207","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8f9516daedd67097a0c6e463fcb7a42b5ee9d477 c4b70c1512b8f9f33f23c2c8196dfd1210207681 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8f9516daedd67097a0c6e463fcb7a42b5ee9d477 806586e33891066487db1f002be3d455cda6b516 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8f9516daedd67097a0c6e463fcb7a42b5ee9d477 05ed733b65ab977dd931e7f7ac0f62fdb81205c2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.17","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.17 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.39 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/sched/sch_dualpi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c4b70c1512b8f9f33f23c2c8196dfd1210207681","status":"affected","version":"8f9516daedd67097a0c6e463fcb7a42b5ee9d477","versionType":"git"},{"lessThan":"806586e33891066487db1f002be3d455cda6b516","status":"affected","version":"8f9516daedd67097a0c6e463fcb7a42b5ee9d477","versionType":"git"},{"lessThan":"05ed733b65ab977dd931e7f7ac0f62fdb81205c2","status":"affected","version":"8f9516daedd67097a0c6e463fcb7a42b5ee9d477","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/sched/sch_dualpi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.17"},{"lessThan":"6.17","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.39","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.39","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc1","versionStartIncluding":"6.17","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: dualpi2: fix GSO backlog accounting\n\nWhen DualPI2 splits a GSO skb into N segments, it propagates N\nadditional packets to its parent before returning NET_XMIT_SUCCESS.\nThe parent then accounts for the original skb once more, leaving its\nqlen one larger than the number of packets actually queued.\n\nWith QFQ as the parent, after all real packets are dequeued, QFQ still\nhas a non-zero qlen while its in-service aggregate has no active\nclasses. qfq_choose_next_agg() returns NULL and qfq_dequeue() passes\nthe result to qfq_peek_skb(), causing a NULL pointer dereference.\n\nFollow the same pattern used by tbf_segment() and taprio: count only\nsuccessfully queued segments, propagate the difference between the\noriginal skb and those segments, and return NET_XMIT_SUCCESS whenever\nat least one segment was queued."}],"providerMetadata":{"dateUpdated":"2026-07-20T16:27:54.447Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c4b70c1512b8f9f33f23c2c8196dfd1210207681"},{"url":"https://git.kernel.org/stable/c/806586e33891066487db1f002be3d455cda6b516"},{"url":"https://git.kernel.org/stable/c/05ed733b65ab977dd931e7f7ac0f62fdb81205c2"}],"title":"net/sched: dualpi2: fix GSO backlog accounting","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64207","datePublished":"2026-07-20T16:27:54.447Z","dateReserved":"2026-07-19T15:36:31.769Z","dateUpdated":"2026-07-20T16:27:54.447Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-20 17:18:22","lastModifiedDate":"2026-07-20 17:18:22","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64207","Ordinal":"1","Title":"net/sched: dualpi2: fix GSO backlog accounting","CVE":"CVE-2026-64207","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64207","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: dualpi2: fix GSO backlog accounting\n\nWhen DualPI2 splits a GSO skb into N segments, it propagates N\nadditional packets to its parent before returning NET_XMIT_SUCCESS.\nThe parent then accounts for the original skb once more, leaving its\nqlen one larger than the number of packets actually queued.\n\nWith QFQ as the parent, after all real packets are dequeued, QFQ still\nhas a non-zero qlen while its in-service aggregate has no active\nclasses. qfq_choose_next_agg() returns NULL and qfq_dequeue() passes\nthe result to qfq_peek_skb(), causing a NULL pointer dereference.\n\nFollow the same pattern used by tbf_segment() and taprio: count only\nsuccessfully queued segments, propagate the difference between the\noriginal skb and those segments, and return NET_XMIT_SUCCESS whenever\nat least one segment was queued.","Type":"Description","Title":"net/sched: dualpi2: fix GSO backlog accounting"}]}}}