Impact
This kernel bug causes an infinite loop in the sfq dequeue logic when the quantum value overflows to the negative extreme. The overflow occurs for devices with an excessively large MTU, causing the quantum to be set to the signed MIN value. Twice adding this MIN value toggles the slot allotment between INT_MIN and zero, spinning the scheduler lock irrecoverably. The result is a soft lockup that consumes CPU resources, effectively rendering the system unusable for affected threads.
Affected Systems
All Linux kernel releases that lack the commit introducing quantum clamping are affected. The issue was identified in the net/sched/ sfq subsystem and applies to the generic Linux kernel regardless of distribution or architecture. No specific vendor versions are listed, implying the flaw exists in any unpatched kernel.
Risk and Exploitability
An attacker with CAP_NET_ADMIN rights inside a user namespace can trigger the condition by creating a dummy interface with a legitimate MTU near the 2GB boundary. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating low public exploitation likelihood. However, local privileged exploitation remains feasible and can lead to a denial of service via sustained CPU lockup. The attack vector is inferred to be local privileged input on a susceptible device.
OpenCVE Enrichment
Debian DLA
Debian DSA