Impact
The vulnerability is a signed integer overflow in the fq_pie packet scheduler. When a network device with an excessively large MTU is bound to fq_pie, the default quantum calculation yields 0x80000000, which overflows the signed deficit counter inside fq_pie_qdisc_dequeue. This overflow drives the counter to INT_MIN and causes an infinite loop, resulting in a soft lockup that disables packet processing and leads to a denial of service on the affected system. The weakness is a classic signed integer overflow (CWE‑190).
Affected Systems
The affected product is the Linux kernel itself, through the fq_pie packet scheduler. Any Linux installation that enables fq_pie on a network interface capable of an oversized MTU – such as a dummy or virtual device with max_mtu configured to allow values close to the maximum signed 32‑bit integer – is vulnerable. The issue is not tied to a particular distribution version; the fix is present in later kernel releases, so the risk applies to any system running an unsorted kernel version that contains the unpatched fq_pie code.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploits. However, the CVSS‑style severity is high because an attacker with CAP_NET_ADMIN in a user namespace can configure a device with a malicious MTU, trigger the overflow, and cause a soft lockup. The path to exploitation requires privileged network configuration tools; it is not exploitable over the network unless a privileged user has local access. Thus the threat remains significant for privileged users or compromised local accounts.
OpenCVE Enrichment
Debian DLA
Debian DSA