CVE-2026-52984: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: fix queue limit check to include reordered packets The queue limit check in netem_enqueue() uses q->t_len which only counts packets in the internal tfifo. Packets placed in sch->q by the reorder path (__qdisc_enqueue_head) are not counted, allowing the total queue occupancy to exceed sch->limit under reordering. Include sch->q.qlen in the limit check.

Affected products

  • Linux Linux Kernel: from 5.4.288, before 5.5 (fixed in 5.5); from 5.10.232, before 5.10.258 (fixed in 5.10.258); from 5.15.175, before 5.15.209 (fixed in 5.15.209); from 6.1.121, before 6.1.175 (fixed in 6.1.175); from 6.6.67, before 6.6.141 (fixed in 6.6.141); from 6.12.6, before 6.12.91 (fixed in 6.12.91); …

Published 2026-06-24. Last modified 2026-07-14.