Impact
The Linux kernel’s fq_codel traffic shaper originally set its scheduling quantum directly from the MTU of the attached device without clamping it. When a device such as a dummy interface accepts an abnormally large MTU—on the order of 2 GiB—the calculation overflows the signed deficit counter, causing the dequeue routine to enter an infinite loop. The resulting kernel soft lockup stalls the interface, and because the CoDel algorithm’s drop check always succeeds with the oversized MTU, traffic drops are completely disabled. The effect is a denial of service for all packets traversing the affected queueing discipline.
Affected Systems
Any Linux kernel that includes the legacy fq_codel implementation and has not incorporated the fix that clamps the default quantum and MTU values is affected. The vulnerability is actionable when a network device, especially a dummy interface, is configured with an MTU beyond the normal maximum (e.g., 2 GiB).
Risk and Exploitability
The probability of exploitation in the wild is very low, with an EPSS score of less than 1 % and no listing in CISA’s KEV catalog. Nevertheless, the flaw requires CAP_NET_ADMIN privileges, meaning that a local user with administrative rights or a compromised process could trigger the soft lockup. Once triggered, the kernel becomes unresponsive to traffic on the affected qdisc, and the CoDel mechanism ceases to drop or mark packets, potentially disrupting network flows until the system is rebooted or the configuration is corrected.
OpenCVE Enrichment
Debian DLA
Debian DSA