Impact
The vulnerability arises when the Linux kernel's queuing discipline subsystem accepts a user‑supplied size table that amplifies the packet length calculation. A malicious table can inflate the packet length to roughly 1 GiB, causing per‑flow deficit schedulers such as DRR or ETS to spin billions of times while holding the qdisc lock. This unbounded loop triggers a kernel soft lockup and, if the kernel is configured with panic on soft lockup, it results in a system crash. The impact is a full system denial of service, potentially causing loss of availability for all users on the affected node.
Affected Systems
All Linux kernel builds that enable net/sched (CONFIG_NET_SCHED=y) and a deficit scheduler such as DRR or ETS. The specific affected products are the Linux kernel itself; vendor or distribution information is not provided, and the version range is unspecified. The vulnerability can be reproduced when the kernel is loaded with a DRR or ETS root qdisc containing a crafted TCA_STAB that amplifies qdisc_pkt_len to ~1 GiB and a class with a quantum of 1.
Risk and Exploitability
The EPSS score is listed as <1 %, indicating that exploitation is considered unlikely at this time, and the vulnerability is not currently in CISA’s KEV catalog. However, the CVSS score is not provided, but given the severity of a kernel‑level soft lockup, any successful exploitation would be highly damaging. Attackers must have the ability to create a net/sched configuration, typically requiring CAP_NET_ADMIN privileges – achievable locally or from a user‑namespace with namespace‑local CAP_NET_ADMIN. The attack path requires no network exposure; it is a local privilege misuse scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA