From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 903A337F32B for ; Sat, 15 Aug 2026 06:32:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775523; cv=none; b=RC5AyKdctkI2ROcpAu3bAcMK2A+7U08TaCRqYLb2DwramLTkfCIYTHGskjklJfMJMEpmbB4ukE0zAOK2sd/7VLAk3Wb20ItAiHrOO5nJ3Wm9vLowFE04a3qcvhstCt8XSR55fa88/wfcqJGlNZ84ngVYJWSA/jSO+6d1vyQ77QY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775523; c=relaxed/simple; bh=KntmAJO26rafpfsx4ioRV54Q588gAUB8bvsUJbvoNg4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=XiKEUAnYNREhhlMypUH/uSppsCuULDhF7GGrzIMYyt59kJc6uYYIFz9iRmTTGApIQvtGUuQbNhVVtw7NSW6N1IqzNCDFk7hZDbLaCuOAl7eHrTK62iSj9aS9bbdjG1UHpqAD9JA0Bd7glCf0k1w+agCqHbvU0nqBofhuFcqB2Sg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=WXzBcED7; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="WXzBcED7" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E0C191F00A3A; Sat, 15 Aug 2026 06:32:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786775522; bh=h2YYeVuZ5gOghcVXzh0IgAR71W7jsu8mCO7zx8PEXA4=; h=From:To:Cc:Subject:Date:Reply-To; b=WXzBcED7BPHmex65o1twJPIFixxU8B+zmjrDfrr7IrCKKZcEQsZN8xsxmMOqepRau JxZZ8S2J47yhjSqgO9C4iPcwLJUN3bJMh24QpbSaM0MTnouPDBkUkBZX2C/Z7e4N1K crFsE2itgRnsGCUSip7EjsG1ILJ4jSMq7C1KmUvw= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74266: net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Date: Sat, 15 Aug 2026 15:09:53 +0900 Message-ID: <2026081543-CVE-2026-74266-1cd6@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4575; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Q+/2hIq712exqw3t/a+nGdV4a+/buIFvDDg+Qq3o9F0=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNjMw7F9pofzS0f+l1UuIL215GtkVi6Qp5y7d3bfp0s 3hCVjprRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzE4RXDPLOJy63lpC7GVrNF yJW/5HWr9hMoYJify3XMeVHPW77o8++lHiS8D43ov8kBAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Whenever dualpi2 drops packets during peek, it calls qdisc_tree_reduce_backlog. An issue arises because it calls qdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops to zero, but peek returns an skb, the parent's qlen_notify callback will be executed even though dualpi2 still has 1 packet on the queue and, thus, mistakenly deactivates the parent's class which leads to a null-ptr-deref: [ 101.427314][ T599] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] SMP KASAN NOPTI [ 101.427755][ T599] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f] [ 101.428048][ T599] CPU: 2 UID: 0 PID: 599 Comm: ping Not tainted 7.1.0-rc5-00284-gbce53c430ed7 #102 PREEMPT(full) [ 101.428400][ T599] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 101.428608][ T599] RIP: 0010:qfq_dequeue (net/sched/sch_qfq.c:1150) sch_qfq [ 101.428821][ T599] Code: 00 fc ff df 80 3c 02 00 0f 85 46 0c 00 00 4c 8d 73 48 48 89 9d b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <80> 3c 02 00 0f 85 2d 0c 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b All code [ 101.429348][ T599] RSP: 0018:ffff8881110df4f0 EFLAGS: 00010216 [ 101.429541][ T599] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: dffffc0000000000 [ 101.429763][ T599] RDX: 0000000000000009 RSI: 00000024c0000000 RDI: ffff88811436c2b0 [ 101.429985][ T599] RBP: ffff88811436c000 R08: ffff88811436c280 R09: 1ffff11021277523 [ 101.430206][ T599] R10: 1ffff11021277526 R11: 1ffff11021277527 R12: 00000024c0000000 [ 101.430423][ T599] R13: ffff88811436c2b8 R14: 0000000000000048 R15: 0000000020000000 [ 101.430642][ T599] FS: 00007f61813e1c40(0000) GS:ffff8881691ef000(0000) knlGS:0000000000000000 [ 101.430913][ T599] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 101.431100][ T599] CR2: 00005651650850a8 CR3: 000000010ca0b000 CR4: 0000000000750ef0 [ 101.431320][ T599] PKRU: 55555554 [ 101.431433][ T599] Call Trace: [ 101.431544][ T599] [ 101.431628][ T599] __qdisc_run (net/sched/sch_generic.c:322 net/sched/sch_generic.c:427 net/sched/sch_generic.c:445) [ 101.431792][ T599] ? dev_qdisc_enqueue (./include/trace/events/qdisc.h:49 (discriminator 22) net/core/dev.c:4176 (discriminator 22)) [ 101.431941][ T599] __dev_queue_xmit (./include/net/pkt_sched.h:120 ./include/net/pkt_sched.h:117 net/core/dev.c:4292 net/core/dev.c:4831) Fix this by only calling qdisc_tree_reduce_backlog in peek after the qlen is restored. The Linux kernel CVE team has assigned CVE-2026-74266 to this issue. Affected and fixed versions =========================== Issue introduced in 6.17 with commit 8f9516daedd67097a0c6e463fcb7a42b5ee9d477 and fixed in 6.18.40 with commit bd851b10daee7199a658458b8ce250e95a334500 Issue introduced in 6.17 with commit 8f9516daedd67097a0c6e463fcb7a42b5ee9d477 and fixed in 7.1.5 with commit 466f29477cae2bd1982a066d518a9b20c5a37924 Issue introduced in 6.17 with commit 8f9516daedd67097a0c6e463fcb7a42b5ee9d477 and fixed in 7.2-rc1 with commit 15cd0c93bf4f892d66bc7a93667e2357b5673365 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74266 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/sched/sch_dualpi2.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/bd851b10daee7199a658458b8ce250e95a334500 https://git.kernel.org/stable/c/466f29477cae2bd1982a066d518a9b20c5a37924 https://git.kernel.org/stable/c/15cd0c93bf4f892d66bc7a93667e2357b5673365