PatchSiren cyber security CVE debrief
CVE-2026-97966 Linux CVE debrief
A vulnerability in the Linux kernel has been resolved, involving the HTB scheduler topology not being properly reset before freeing queues in the otceontx2-pf driver. This oversight could lead to PRIO_ANCHOR/RR_PRIO settings surviving in the shared scheduler pool and affecting later allocations. Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations. The CVE record and source references provide details on the vulnerability and its resolution in the Linux kernel.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Linux kernel and otceontx2-pf driver configurations should assess exposure and prioritize verification. This includes operators, platform administrators, vulnerability management teams, and security teams who manage Linux kernel versions and otceontx2-pf driver configurations.
Why it matters
Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations due to a resolved vulnerability involving HTB scheduler topology and queue freeing.
- Verification of Linux kernel versions and otceontx2-pf driver configurations is necessary to ensure proper scheduler topology and queue freeing
- Exposure to potential scheduler pool corruption and incorrect PRIO_ANCHOR/RR_PRIO settings
Technical summary
The Linux kernel vulnerability involves the HTB scheduler topology not being properly reset before freeing queues in the otceontx2-pf driver. This can lead to PRIO_ANCHOR/RR_PRIO settings surviving in the shared scheduler pool and affecting later allocations. The vulnerability has been resolved through the addition of otx2_qos_reset_schq_topology() and otx2_qos_free_hw_schq() to zero TL4 through TL2 TOPOLOGY before each schq is returned to the AF during hierarchy teardown and cfg rollback. Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations.
Defensive priority
Defenders should assess exposure and prioritize verification of Linux kernel versions and otceontx2-pf driver configurations.
Recommended defensive actions
- Assess exposure by verifying Linux kernel versions and otceontx2-pf driver configurations
- Prioritize verification of scheduler topology and queue freeing in otceontx2-pf driver
- Review and apply patches or updates for the Linux kernel and otceontx2-pf driver
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source references provide details on the vulnerability and its resolution in the Linux kernel. Evidence is limited to public CVE details and Linux kernel patch references. Defenders should verify Linux kernel versions and otceontx2-pf driver configurations for exposure. The vulnerability involves the HTB scheduler topology not being properly reset before freeing queues in the otceontx2-pf driver.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97966 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97966
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97966 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97966
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0aa2dd6eaa347c7aab448df0eec0afcfe7489885
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2df186418e17b30b319cf9ff81aad137692ab107
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/621c99be42e3f5cb68a6af9480a255218a761c4e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ef39fca8508597fa565cf2be72a884a712fb98af
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.