PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97966 Linux CVE debrief

A vulnerability in the Linux kernel has been resolved, involving the HTB scheduler topology not being properly reset before freeing queues in the otceontx2-pf driver. This oversight could lead to PRIO_ANCHOR/RR_PRIO settings surviving in the shared scheduler pool and affecting later allocations. Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations. The CVE record and source references provide details on the vulnerability and its resolution in the Linux kernel.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Linux kernel and otceontx2-pf driver configurations should assess exposure and prioritize verification. This includes operators, platform administrators, vulnerability management teams, and security teams who manage Linux kernel versions and otceontx2-pf driver configurations.

Why it matters

Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations due to a resolved vulnerability involving HTB scheduler topology and queue freeing.

  • Verification of Linux kernel versions and otceontx2-pf driver configurations is necessary to ensure proper scheduler topology and queue freeing
  • Exposure to potential scheduler pool corruption and incorrect PRIO_ANCHOR/RR_PRIO settings

Technical summary

The Linux kernel vulnerability involves the HTB scheduler topology not being properly reset before freeing queues in the otceontx2-pf driver. This can lead to PRIO_ANCHOR/RR_PRIO settings surviving in the shared scheduler pool and affecting later allocations. The vulnerability has been resolved through the addition of otx2_qos_reset_schq_topology() and otx2_qos_free_hw_schq() to zero TL4 through TL2 TOPOLOGY before each schq is returned to the AF during hierarchy teardown and cfg rollback. Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations.

Defensive priority

Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations.

Recommended defensive actions

  • Assess exposure by verifying Linux kernel versions and otceontx2-pf driver configurations
  • Prioritize verification of scheduler topology and queue freeing in otceontx2-pf driver
  • Review and apply patches or updates for the Linux kernel and otceontx2-pf driver
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source references provide details on the vulnerability and its resolution in the Linux kernel. Evidence is limited to public CVE details and Linux kernel patch references. Defenders should verify Linux kernel versions and otceontx2-pf driver configurations for exposure. The vulnerability involves the HTB scheduler topology not being properly reset before freeing queues in the otceontx2-pf driver.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97966 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97966

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97966 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97966

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0aa2dd6eaa347c7aab448df0eec0afcfe7489885

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2df186418e17b30b319cf9ff81aad137692ab107

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/621c99be42e3f5cb68a6af9480a255218a761c4e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ef39fca8508597fa565cf2be72a884a712fb98af

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.