CVE-2026-52997 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_dualpi2: drain both C-queue and L-queue in dualpi2_change() Fix dualpi2_change() to correctly enforce updated limit and memlimit values after a configuration change of the dualpi2 qdisc. Before this patch, dualpi2_change() always attempted to dequeue packets via the root qdisc (C-queue) when reducing backlog or memory usage, and unconditionally assumed that a valid skb will be returned. When traffic classification results in packets being queued in the L-queue while the C-queue is empty, this leads to a NULL skb dereference during limit or memlimit enforcement. This is fixed by first dequeuing from the C-queue path if it is non-empty. Once the C-queue is empty, packets are dequeued directly from the L-queue. Return values from qdisc_dequeue_internal() are checked for both queues. When dequeuing from the L-queue, the parent qdisc qlen and backlog counters are updated explicitly to keep overall qdisc statistics consistent.
A vulnerability in the Linux kernel's DualPI2 queuing discipline can cause a NULL pointer dereference. This issue arises in the 'dualpi2_change()' function, which improperly manages packet dequeueing from two queues (C-queue and L-queue) after configuration changes. The flaw occurs because the function assumes it will always receive a valid packet when reducing backlog or memory usage. If packets are queued in the L-queue while the C-queue is empty, the function can dereference a NULL pointer, leading to a crash. The vulnerability affects the Linux kernel stable tree.
Users can upgrade to the patched version of the Linux kernel available in the Linux Kernel Git Repository under the stable branch.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3042add80c2c50bd127d570b83319af612efde65 | kernel.org | Patch |
| https://git.kernel.org/stable/c/478ed6b7d2577439c610f91fa8759a4c878a4264 | kernel.org | Patch |
| https://git.kernel.org/stable/c/86cf2eba2056bcf9c41fba260e599bd95bf9943b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.17, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |