Impact
A bug in the HTB qdisc packet classifier allowed an unbounded traversal of inner class filters, creating an infinite loop while holding the qdisc lock. The loop consumes CPU and can trigger a soft lockup or a kernel panic when the system is set to panic on lockup. The vulnerability does not leak data but can bring the affected system to a non‑responsive state, effectively a denial‑of‑service. This is a control‑flow error that fails to enforce a maximum hop count during classification.
Affected Systems
Any Linux kernel image that builds with the network scheduler support, HTB qdisc, and U32 classification, such as kernel configurations that enable CONFIG_NET_SCHED, CONFIG_NET_SCH_HTB, CONFIG_NET_CLS_U32, and CONFIG_LOCKUP_DETECTOR. Common distributions run these options in default kernels, so most standard installations could be affected unless the patch has been applied.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low realistic exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. An attacker can trigger the flaw by creating a HTB/qdisc chain with a self‑referencing or cyclic inner‑class filter, which can be done by an unprivileged local user who has the CAP_NET_ADMIN capability (for example via unshare –Urn). Because the bug requires local configuration, it is a local privilege‑escalation‑to‑Denial‑of‑Service vector rather than a remote attack.
OpenCVE Enrichment
Debian DLA
Debian DSA