In the Linux kernel, the following vulnerability has been resolved:
net_sched: fix skb memory leak in deferred qdisc drops
When the network stack cleans up the deferred list via qdiscrunend(), it operates on the root qdisc. If the root qdisc do not implement the TCQFDEQUEUEDROPS flag the packets queue to free are never freed and gets stranded on the child's local tofree list.
Fix this by making qdiscdequeuedrop() aware of the root qdisc. It fetches the root qdisc and check for the TCQFDEQUEUEDROPS flag. If the flag is present, the packet is appended directly to the root's tofree list. Otherwise, drop it directly as it was done before the optimization was implemented.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53079.json"
}