{"id":"CVE-2026-97966","published":"2026-09-25T11:17:24.413","lastModified":"2026-09-25T11:17:24.413","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: reset HTB scheduler topology before freeing queues\n\nHTB offload programs NIX_AF_TLxX_TOPOLOGY on QoS-allocated scheduler\nqueues via otx2_qos_txschq_set_parent_topology(), but teardown freed\nthose queues without clearing TOPOLOGY.  The AF only restores PARENT and\nSCHEDULE on free, so PRIO_ANCHOR/RR_PRIO settings can survive in the\nshared scheduler pool and affect later allocations.\n\nAdd otx2_qos_reset_schq_topology() and otx2_qos_free_hw_schq() to zero\nTL4 through TL2 TOPOLOGY before each schq is returned to the AF during\nhierarchy teardown and cfg rollback.  Skip the aggregation level (TL1):\nit is a per-tx-link queue shared by the PF, default Tx hierarchy and VFs,\nand is not freed back to the AF by nix_txschq_free_one().","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/0aa2dd6eaa347c7aab448df0eec0afcfe7489885","tags":[]},{"url":"https://git.kernel.org/stable/c/2df186418e17b30b319cf9ff81aad137692ab107","tags":[]},{"url":"https://git.kernel.org/stable/c/621c99be42e3f5cb68a6af9480a255218a761c4e","tags":[]},{"url":"https://git.kernel.org/stable/c/ef39fca8508597fa565cf2be72a884a712fb98af","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}