SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-72036

HIGH · CVSS 7.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's multi-queue scheduling mechanism, specifically in the handling of packet dequeue operations, which can lead to kernel panics when non-work-conserving child queues are involved. This issue arises from improper management of packet stashing and dequeueing, potentially causing system instability during normal egress operations. Organizations utilizing Linux systems, particularly those relying on advanced traffic scheduling features, should prioritize addressing this vulnerability to maintain system reliability and performance.

CVE
CVE-2026-72036
Severity
HIGH
CVSS
7.8
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked multiq_dequeue() takes a packet from a band's child with a direct ->dequeue() call after multiq_peek() peeked it. When the child is non-work-conserving the peek stashes the skb in the child's gso_skb, so the direct dequeue returns a different skb and orphans the stash, desyncing the child's qlen/backlog. With a qfq child reached through a peeking parent (e.g. tbf) this re-enters the child on an emptied list and dereferences NULL, panicking the kernel from softirq on ordinary egress. Take the packet through qdisc_dequeue_peeked(), as sch_prio already does and as sch_red and sch_sfb were just fixed to do. The helper is a no-op when the child has no stash, so a work-conserving child is unaffected.