<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:57:27 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-56770 — net/sched: netem: account for backlog updates from child qdisc</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-56770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: netem: account for backlog updates from child qdisc&lt;/p&gt;
&lt;p&gt;In general, &amp;#39;qlen&amp;#39; of any classful qdisc should keep track of the
number of packets that the qdisc itself and all of its children holds.
In case of netem, &amp;#39;qlen&amp;#39; only accounts for the packets in its internal
tfifo. When netem is used with a child qdisc, the child qdisc can use
&amp;#39;qdisc_tree_reduce_backlog&amp;#39; to inform its parent, netem, about created
or dropped SKBs. This function updates &amp;#39;qlen&amp;#39; and the backlog statistics
of netem, but netem does not account for changes made by a child qdisc.
&amp;#39;qlen&amp;#39; then indicates the wrong number of packets in the tfifo.
If a child qdisc creates new SKBs during enqueue and informs its parent
about this, netem&amp;#39;s &amp;#39;qlen&amp;#39; value is increased. When netem dequeues the
newly created SKBs from the child, the &amp;#39;qlen&amp;#39; in netem is not updated.
If &amp;#39;qlen&amp;#39; reaches the configured sch-&amp;gt;limit, the enqueue function stops
working, even though the tfifo is not full.&lt;/p&gt;
&lt;p&gt;Reproduce the bug:
Ensure that the sender machine has GSO enabled. Configure netem as root
qdisc and tbf as its child on the outgoing interface of the machine
as follows:
$ tc qdisc add dev &amp;lt;oif&amp;gt; root handle 1: netem delay 100ms limit 100
$ tc qdisc add dev &amp;lt;oif&amp;gt; parent 1:0 tbf rate 50Mbit burst 1542 latency 50ms&lt;/p&gt;
&lt;p&gt;Send bulk TCP traffic out via this interface, e.g., by running an iPerf3
client on the machine. Check the qdisc statistics:
$ tc -s qdisc show dev &amp;lt;oif&amp;gt;&lt;/p&gt;
&lt;p&gt;Statist…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: netem: account for backlog updates from child qdisc&lt;/p&gt;
&lt;p&gt;In general, &amp;#39;qlen&amp;#39; of any classful qdisc should keep track of the
number of packets that the qdisc itself and all of its children holds.
In case of netem, &amp;#39;qlen&amp;#39; only accounts for the packets in its internal
tfifo. When netem is used with a child qdisc, the child qdisc can use
&amp;#39;qdisc_tree_reduce_backlog&amp;#39; to inform its parent, netem, about created
or dropped SKBs. This function updates &amp;#39;qlen&amp;#39; and the backlog statistics
of netem, but netem does not account for changes made by a child qdisc.
&amp;#39;qlen&amp;#39; then indicates the wrong number of packets in the tfifo.
If a child qdisc creates new SKBs during enqueue and informs its parent
about this, netem&amp;#39;s &amp;#39;qlen&amp;#39; value is increased. When netem dequeues the
newly created SKBs from the child, the &amp;#39;qlen&amp;#39; in netem is not updated.
If &amp;#39;qlen&amp;#39; reaches the configured sch-&amp;gt;limit, the enqueue function stops
working, even though the tfifo is not full.&lt;/p&gt;
&lt;p&gt;Reproduce the bug:
Ensure that the sender machine has GSO enabled. Configure netem as root
qdisc and tbf as its child on the outgoing interface of the machine
as follows:
$ tc qdisc add dev &amp;lt;oif&amp;gt; root handle 1: netem delay 100ms limit 100
$ tc qdisc add dev &amp;lt;oif&amp;gt; parent 1:0 tbf rate 50Mbit burst 1542 latency 50ms&lt;/p&gt;
&lt;p&gt;Send bulk TCP traffic out via this interface, e.g., by running an iPerf3
client on the machine. Check the qdisc statistics:
$ tc -s qdisc show dev &amp;lt;oif&amp;gt;&lt;/p&gt;
&lt;p&gt;Statist…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-56770</guid>
    </item>
  </channel>
</rss>
