---
id: CVE-2026-98010
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/sched: drr: clamp quantum in change class

  drr_change_class() rejects explicit quantum==0 but falls back to
  psched_mtu() with no floor
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/sched: drr: clamp quantum in change class

  drr_change_class() rejects explicit quantum==0 but falls back to
  psched_mtu() with no floor. With a crafted size table qd…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 13d2a1d2b032de08d7dcab6a1edcd47802681f96 <
    dc8b374214ef5bba4882bbd95b361e42555cfc0d
  - >-
    Linux >= 13d2a1d2b032de08d7dcab6a1edcd47802681f96 <
    d43cded350fe1218493ad3d37a276aff14108ae6
  - >-
    Linux >= 13d2a1d2b032de08d7dcab6a1edcd47802681f96 <
    8f756ae1c87414ce9cc21b30e6e4c036d6e9e80b
  - >-
    Linux >= 13d2a1d2b032de08d7dcab6a1edcd47802681f96 <
    8382abec0f1568d0a5590d75a3df92f23fcf5196
  - Linux 2.6.29
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:29.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98010'
references:
  - url: 'https://git.kernel.org/stable/c/8382abec0f1568d0a5590d75a3df92f23fcf5196'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8f756ae1c87414ce9cc21b30e6e4c036d6e9e80b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d43cded350fe1218493ad3d37a276aff14108ae6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc8b374214ef5bba4882bbd95b361e42555cfc0d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.859Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net/sched: drr: clamp quantum in change class

drr_change_class() rejects explicit quantum==0 but falls back to
psched_mtu() with no floor. With a crafted size table qdisc_pkt_len
reaches ~2 GiB, so quantum=1 (or a zero psched_mtu on a headerless
device) makes the deficit-refill loop spin under the qdisc lock.

Add clamp_t(u32, quantum, 256, 1<<20) after the zero reject and on the
fallback path. The explicit-zero reject is preserved.

Conditions to recreate the bug:
  CONFIG_NET_SCH_DRR=y. Requires CAP_NET_ADMIN (namespace-local via
  unshare -Urn suffices).

  tc qdisc add dev dummy0 root drr
  tc class add dev dummy0 parent 1: classid 1:1 drr quantum 1

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
