Impact
The vulnerability lies in the Linux kernel’s Fair Queue (FQ) traffic control module. The kernel allows an administrator to change the quantum and initial quantum parameters of an FQ qdisc without properly enforcing the original clamping bounds. This omission lets an attacker set a quantum value that is too small, triggering the small‑quantum deficit spin that the original clamp was meant to suppress. The result is excessive CPU consumption and a denial of service for the affected networking stack, potentially affecting all traffic processed by the compromised device.
Affected Systems
Any Linux system running a kernel with the FQ traffic control scheduler enabled (CONFIG_NET_SCH_FQ=y). The issue can be triggered by any process that can acquire the CAP_NET_ADMIN capability within a network namespace, which can be obtained on the local host using commands such as unshare -Urn. The exact kernel versions are not specified in the current advisory; all kernels containing the unpatched FQ module are potentially affected.
Risk and Exploitability
The EPSS score indicates a probability of exploitation below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is unlikely. However, the impact of successful exploitation is limited to the local machine or its namespaces and requires a user with network administration privileges. While the potential damage is a local denial of service, the ease of exploitation is moderate due to the need for CAP_NET_ADMIN and knowledge of the specific qdisc commands.
OpenCVE Enrichment