Executive brief
The Linux kernel's taprio traffic scheduler contains a flaw in how it retrieves network packets from child queue management disciplines. When using certain queue types (like qfq), the scheduler incorrectly bypasses buffered packets, causing the kernel to crash with a NULL pointer error during normal network transmission. This can disrupt network services and cause system instability on affected servers.
Technical details
The vulnerability is a NULL pointer dereference in the taprio qdisc scheduler (net/sched/sch_taprio.c). When the software path peeks at a non-work-conserving child qdisc, the child stashes the peeked skb in its gso_skb field. The vulnerable code then calls child->ops->dequeue() directly, which ignores this stash, orphans the peeked skb, and desyncs the child's qlen/backlog counters. With a qfq child qdisc, this causes re-entry on an emptied list and results in NULL pointer dereference from softirq context during egress packet processing. The fix replaces the direct dequeue call with qdisc_dequeue_peeked(), which properly retrieves the stashed packet first. Attack vector is local/adjacent (kernel network processing path), no authentication required. Patch is available in upstream kernel and stable branches.
Affected products
- Linux Linux kernel prior to e056e1dfcddca877dd46d704e8ec9860cfc9ec44
Timeline
- 2026-08-15: disclosed
- 2026-07-28: patched: Upstream fix committed; stable branch backports followed