Executive brief
The Linux kernel's Fair Queuing (FQ) network scheduler contained a validation gap that allowed administrators with CAP_NET_ADMIN privileges to override safety limits on packet queue size parameters. By setting excessively small quantum values via the tc qdisc command, an attacker could trigger inefficient packet processing (deficit spin) that degrades network performance and causes CPU overhead on affected systems.
Technical details
The vulnerability exists in the FQ qdisc change path (sch_fq.c), which previously accepted TCA_FQ_QUANTUM parameter values in the range [1, INT_MAX], while the initialization path (fq_init) clamped the value to [1, 1<<20]. A local attacker holding CAP_NET_ADMIN capability could invoke tc qdisc change to override the init clamp by setting quantum to 1, bypassing the intended bounds check. This exposes the "small-quantum deficit spin" condition that the init clamp was designed to prevent. The fix narrows iq_range.max to 1<<20 for parse-time rejection and applies clamp_t() to enforce [256, 1<<20] bounds in both fq_change() and fq_init(). Exploitation requires CONFIG_NET_SCH_FQ=y kernel configuration and local admin or namespace-level root access.
Affected products
- Linux Linux kernel versions with FQ qdisc (likely 5.0 and later, prior to patch commit 094cc07f98dfe70a34e2a1923af17fd29b8cf622)
Timeline
- 2026-09-17: disclosed: CVE-2026-90050 published
- 2026-09-05: patched: Upstream kernel fix merged (commit 094cc07f98dfe70a34e2a1923af17fd29b8cf622)