Executive brief
The Linux kernel's scheduler queue management (HFSC) had a logic error that could prevent network packets from being properly dequeued and transmitted. When a child queue became empty during packet processing, the scheduler would incorrectly mark the parent queue as inactive even if other child queues still had pending traffic, causing those packets to stall indefinitely and network communication to hang.
Technical details
A double-passive transition vulnerability in the Linux kernel's net/sched HFSC (Hierarchical Fair Service Curve) scheduler. The update_vf() function is called twice on the same class during a single dequeue cycle when a child qdisc drops its last packets: once from qdisc_tree_reduce_backlog() when the child empties, and again from hfsc_dequeue() to charge dequeued bytes. On the second call, the already-passive class incorrectly triggers go_passive again, causing the stale flag to propagate to the parent and decrement its cl_nactive a second time. This can drive an active parent with other backlogged children to an inactive state, removing it from the vttree and preventing those sibling queues from ever being dequeued. The fix restricts go_passive arming to only active classes, preventing double-passivation while maintaining correct byte accounting. This is a kernel-internal logic bug with no direct exploit vector but significant availability impact on network performance.
Affected products
- Linux Linux kernel affected versions unspecified in advisory
Timeline
- 2026-08-15: disclosed