CVE-2026-97966
Błąd w jądrze Linux umożliwia przetrwanie ustawień priorytetów w pulach schedulerów po zwolnieniu kolejek.
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: reset HTB scheduler topology before freeing queues HTB offload programs NIX_AF_TLxX_TOPOLOGY on QoS-allocated scheduler queues via otx2_qos_txschq_set_parent_topology(), but teardown freed those queues without clearing TOPOLOGY. The AF only restores PARENT and SCHEDULE on free, so PRIO_ANCHOR/RR_PRIO settings can survive in the shared scheduler pool and affect later allocations. Add otx2_qos_reset_schq_topology() and otx2_qos_free_hw_schq() to zero TL4 through TL2 TOPOLOGY before each schq is returned to the AF during hierarchy teardown and cfg rollback. Skip the aggregation level (TL1): it is a per-tx-link queue shared by the PF, default Tx hierarchy and VFs, and is not freed back to the AF by nix_txschq_free_one().
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-25 11:17:24 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:18:21 UTC |
- https://git.kernel.org/stable/c/0aa2dd6eaa347c7aab448df0eec0afcfe7489885 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/16c5c8ea5017952ff14c87626a45359d195dda6f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/2df186418e17b30b319cf9ff81aad137692ab107 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/621c99be42e3f5cb68a6af9480a255218a761c4e (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/ef39fca8508597fa565cf2be72a884a712fb98af (416baaa9-dc9f-4396-8d5f-8c081fb06d67)