CVE-2026-22999
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/01/2026
Last modified:
25/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/sched: sch_qfq: do not free existing class in qfq_change_class()<br />
<br />
Fixes qfq_change_class() error case.<br />
<br />
cl->qdisc and cl should only be freed if a new class and qdisc<br />
were allocated, or we risk various UAF.



