Impact
The Linux kernel flaw permits unprivileged users or users with the net administration capability to allocate memory for traffic‑control classifiers without properly accounting for it in the memory cgroup. The allocations occur in several classifier modules and a shared action array, all using plain GFP_KERNEL rather than GFP_KERNEL_ACCOUNT. As a result, the kernel pins memory outside the intended memcg quota, allowing a cgroup to consume more memory than permitted and potentially exhausting system memory, which leads to a denial of service.
Affected Systems
All Linux kernel builds that enable the network scheduler, the various classifier modules (cls_basic, cls_bpf, cls_cgroup, cls_flow, cls_flower, cls_fw, cls_matchall, cls_route, cls_u32), memory cgroups, user namespaces, and network namespaces are affected. This includes mainstream distributions that ship recent kernels with CONFIG_NET_SCHED, CONFIG_NET_CLS_* and associated options enabled. The vulnerability is present in the kernel source regardless of the specific distribution, so any host using such a kernel configuration remains at risk unless patched.
Risk and Exploitability
The EPSS score is reported as < 1% and the vulnerability is not listed as a known exploited vulnerability, indicating a low probability of widespread exploitation. However, the attack requires no special privileges beyond CAP_NET_ADMIN or an unprivileged user in a new user and network namespace. The attacker can create a large number of traffic‑control filters via the tc command, causing the uncharged allocations to grow unchecked. Once the memory.cgroup exceeds its quota, system memory is consumed, potentially leading to kernel stalls or reboot. The exploitation path is user‑space only and requires no code execution privileges, making the threat straightforward to execute if the conditions are satisfied.
OpenCVE Enrichment