Impact
The vulnerability arises from a 32‑bit buffer overflow in the backlog calculation for the gred, bfifo, and plug queueing disciplines in the Linux kernel. Backlog and packet length are summed in 32‑bit arithmetic; when the true backlog exceeds 4 GiB the wraparound causes the sum to stay small, so packet admission continues indefinitely. As a result the kernel queue grows without bound, eventually exhausting system memory and triggering an out‑of‑memory condition. The weakness is an integer overflow that leads to uncontrolled resource consumption.
Affected Systems
All Linux kernels that implement the gred, bfifo, or plug queueing disciplines are affected. The patch applies to every Linux kernel version that contained the backlog calculation logic, regardless of specific vendor distribution. No vendor or product name is required beyond the general Linux kernel.
Risk and Exploitability
The exploit requires root privileges and a specialized traffic configuration that forces more than 4 GiB of queued traffic. The EPSS score is indicated as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a low probability of real‑world exploitation. Because the conditions are highly restrictive, the available attack vector is essentially local and would likely be used only for testing or denial‑of‑service experiments.
OpenCVE Enrichment
Debian DLA
Debian DSA