Impact
In the Linux kernel, a defect in the octeontx2-pf driver caused HTB scheduler topology data to persist after queue deallocation. The residual PRIO_ANCHOR/RR_PRIO settings could survive in a shared scheduler pool and influence later queue allocations, allowing a privileged component to indirectly alter QoS parameters for unrelated workloads. This flaw represents improper resource manipulation and could degrade performance or lead to unexpected packet scheduling behavior.
Affected Systems
The vulnerability affects all Linux kernel builds that include the octeontx2 platform networking driver, used on Octeon TX2-based systems. Kernel packages that contain the octeontx2-pf driver and have not been updated after the patch adding otx2_qos_reset_schq_topology and otx2_qos_free_hw_schq are impacted. Specific kernel versions were not listed, so any build with the vulnerable driver is at risk.
Risk and Exploitability
CVSS and EPSS scores are not available and the vulnerability is not in the CISA KEV catalog. The defect exists at kernel privilege level, so a local attacker with kernel or privileged driver access could potentially exploit the residual topology for malicious configuration changes. Because no public exploit is reported, the current risk is moderate, but patching remains the sole mitigative action.
OpenCVE Enrichment