---
id: CVE-2026-90050
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/sched: fq: clamp quantum and initial_quantum in change path

  The fq change path accepts TCA_FQ_QUANTUM in [1, INT_MAX] and
  TCA_FQ_INITIAL_QUANTUM up to INT_MAX, whi…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/sched: fq: clamp quantum and initial_quantum in change path

  The fq change path accepts TCA_FQ_QUANTUM in [1, INT_MAX] and
  TCA_FQ_INITIAL_QUANTUM up to INT_MAX, whi…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d16dac3925be95ad46e986d4b139c9898b6e227f <
    a27498d34c3f429fb6db3aa609569f8154afa175
  - >-
    Linux >= f6b3e3848a5fca63438984acd6d9eceac80814c1 <
    798283cd0fe7ba997f67e5a917f14ab40afa8d9f
  - >-
    Linux >= e35acd56f244d94355f9ab237c2ecc8fba5e6f04 <
    72e9387884554f47b03bfd40fb8b2bf52789c68d
  - >-
    Linux >= 709f34f7c28dc4dd6c40343d101850f11e172312 <
    094cc07f98dfe70a34e2a1923af17fd29b8cf622
  - Linux 7.3-rc1
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:16:53.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90050'
references:
  - url: 'https://git.kernel.org/stable/c/094cc07f98dfe70a34e2a1923af17fd29b8cf622'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/72e9387884554f47b03bfd40fb8b2bf52789c68d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/798283cd0fe7ba997f67e5a917f14ab40afa8d9f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a27498d34c3f429fb6db3aa609569f8154afa175'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.904Z'
epss: 0.00209
epssPercentile: 0.09741
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net/sched: fq: clamp quantum and initial_quantum in change path

The fq change path accepts TCA_FQ_QUANTUM in [1, INT_MAX] and
TCA_FQ_INITIAL_QUANTUM up to INT_MAX, while fq_init() already clamps to
[1, 1<<20]. A user can override the init clamp via tc qdisc change,
restoring the small-quantum deficit spin that the init clamp prevents.

Narrow iq_range.max to 1<<20 so TCA_FQ_INITIAL_QUANTUM is rejected at
parse time. Clamp TCA_FQ_QUANTUM to [256, 1<<20] in fq_change() and
fq_init() quantum to [256, 1<<20] for tiny-MTU devices.

Conditions to recreate the bug:
  CONFIG_NET_SCH_FQ=y. Requires CAP_NET_ADMIN (namespace-local via
  unshare -Urn suffices).

  tc qdisc add dev dummy0 root fq
  tc qdisc change dev dummy0 root fq quantum 1 stab data 32768 size_log 15 cell_log 0

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
