Vulnerability Bulletins

CVE-2026-52984

   
Affected software LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

net/sched: netem: fix queue limit check to include reordered packets

The queue limit check in netem_enqueue() uses q->t_len which only
counts packets in the internal tfifo. Packets placed in sch->q by
the reorder path (__qdisc_enqueue_head) are not counted, allowing
the total queue occupancy to exceed sch->limit under reordering.

Include sch->q.qlen in the limit check.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-52984