Impact
hhf_change() in the Linux kernel stored the hh_flows_limit attribute without any upper bound. A user with CAP_NET_ADMIN in a user namespace can set an arbitrarily large hh_limit value via `tc qdisc change`, which then allows each new heavy‑hitter flow to bypass the flow count check and allocate a fixed‑size, atomically allocated memory block per flow. Because the limit is unbounded, an attacker can trigger unbounded memory consumption, leading to kernel out‑of‑memory conditions and a denial of service.
Affected Systems
The vulnerability affects the Linux kernel’s traffic‑control (tc) subsystem, specifically the hhf qdisc implementation. All Linux‑kernel releases that include this qdisc code are potentially impacted unless the patch has been applied; no specific kernel version is listed in the advisory.
Risk and Exploitability
The risk is significant for hosts that grant CAP_NET_ADMIN to users or processes, as the unbounded hh_flows_limit can be exploited by a privileged local attacker or within a container with elevated privileges. The advisory does not list the CVE in the CISA KEV catalog and EPSS data is unavailable, but the lack of an upper bound combined with the privileged execution path suggests substantial exploitability. The CVSS score is not provided, yet the potential for kernel memory exhaustion and system crash justifies treating the vulnerability as high severity.
OpenCVE Enrichment