SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-72035

HIGH · CVSS 8.2 EPSS 0.57%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's taprio scheduling mechanism, where a direct dequeue call can lead to orphaned packets and kernel panics due to improper handling of peeked packets in non-work-conserving child queuing disciplines. This issue can cause system instability and crashes, particularly when using a qfq child queuing discipline. System administrators and developers managing Linux environments with taprio scheduling should prioritize addressing this vulnerability to ensure kernel stability and prevent potential service disruptions.

CVE
CVE-2026-72035
Severity
HIGH
CVSS
8.2
EPSS
0.57%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked When taprio's software path peeks a non-work-conserving child qdisc, the child stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq() then takes the packet with a direct child ->dequeue() call, which ignores that stash, orphans the peeked skb and desyncs the child's qlen/backlog. With a qfq child this re-enters the child on an emptied list and dereferences NULL, panicking the kernel from softirq on ordinary egress. Take the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb now do. The helper returns the child's stashed skb first and is a no-op when there is none, so a work-conserving child is unaffected and the gated path now consumes the skb whose length was charged to the budget.