Impact
A race condition in the Linux kernel’s traffic‑control (net/sched) cls_api module allows two concurrent tc commands to interfere with each other. When an insert operation loses a race, the error path mistakenly interprets the already‑installed classifier as its own and unlinks it from the active filter chain, silently removing that rule. The consequence is a sudden loss of traffic shaping or filtering rules that can disrupt services relying on exact packet classification, effectively causing a denial of service.
Affected Systems
The flaw affects all publicly released Linux kernel versions that include the cls_api module; no particular version numbers are listed. Administrators should verify that the running kernel is based on a release that contains the upstream patch, which can be confirmed by searching kernel release notes or changelogs for the fix to the cls_api race condition.
Risk and Exploitability
The vulnerability’s exploitation window requires privileged access, typically root or a process with CAP_NET_ADMIN, to invoke tc commands that trigger the insert race. The EPSS score is reported as less than 1 %, indicating a very low probability of real‑world exploitation at this time, and the flaw is not listed in the CISA KEV catalog. Despite the low likelihood, any successful race would silently break traffic control configuration, and the impact is significant in environments where precise packet filtering or quality‑of‑service enforcement is critical.
OpenCVE Enrichment
Debian DLA
Debian DSA