Linux Kernel QFQ Scheduler Class Activation Vulnerability Prevention Patch

Vulnerability

A vulnerability in the Linux kernel's QFQ (Quadratic Fair Queueing) scheduler has been addressed. The issue involved improperly determining whether a class was active by relying on the child queue discipline's length, which could be manipulated. The vulnerability has been resolved by using a more reliable method to check class activation. This patch is preventive, aiming to enhance code consistency and thwart potential exploits that could arise from such manipulations.

Impact

The vulnerability could have allowed for exploitation through manipulations of the queue lengths in the QFQ scheduler, potentially leading to unauthorized access or control over scheduling decisions.

Remediation

Users can apply the patch included in the upstream commit d837fbee92453fbb829f950c8e7cf76207d73f33 to address this vulnerability.

Added: Feb 4, 2026, 5:31 PM
Updated: Feb 4, 2026, 5:31 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.5
remediation
7.7
relevance
2.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.