Impact
The flaw allows an integer overflow when calculating the quantum value for a traffic‑control qdisc, causing the kernel to enter an endless loop in the dequeue routine. The overflow occurs only when a network device advertises an extremely large MTU, leading to a signed multiplication that exceeds bounds and spins the system forever, effectively denying service for that process or potentially the whole machine.
Affected Systems
All Linux kernel versions prior to the fix are vulnerable. The issue manifests when a user with CAP_NET_ADMIN adds an hhf qdisc to any device, especially dummy interfaces that can report MTUs close to the signed integer limit. The affected code applies to the core scheduler and is not tied to a particular distribution version, so any kernel build that did not apply the patch is at risk.
Risk and Exploitability
The EPSS score is reported as less than 1 percent, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires elevated kernel privileges (CAP_NET_ADMIN) in a user namespace, the practical attack surface is limited to privileged users or compromised services that can manipulate network qdiscs. Nonetheless, the impact of an infinite loop is severe, as it can consume CPU resources indefinitely and disrupt kernel scheduling.
OpenCVE Enrichment
Debian DLA
Debian DSA