Impact
A bug in the Linux kernel network scheduler's action API causes undeleted references when a batch of delete actions fails. Each failed delete leaves dangling references to subsequent actions, allowing later delete attempts to succeed blindly and leaving the original object in the identifier database. This reference leak can accumulate over time, exhausting kernel memory or causing other resource constraints to be triggered, ultimately leading to service disruption or a denial of service. The weakness is a classic resource management flaw, classified as a reference leak and broadband as CWE-772.
Affected Systems
All Linux kernel versions that include the net/sched act_api implementation and have not yet incorporated the commit that fixes the reference leak. Specific vendor information is Linux Kernel, with affected products being any distribution that ships the unpatched kernel. Versions affected are unspecified because the vulnerability description does not list them, but the bug exists in the kernel code base until the fix is applied.
Risk and Exploitability
The CVSS score is not publicly available, and the EPSS score is not listed. Consequently, the exact severity rating cannot be provided. The flaw is exploitable by a user with kernel‑level or network configuration privileges that can issue delaction requests to the net/sched subsystem. Because the vulnerability is local and tied to privileged operations, it is unlikely to be exploited remotely without obtaining elevated credentials. The risk to a system is moderate to high if unpatched, as repeated exploitations could lead to sustained memory exhaustion and eventual denial of service.
OpenCVE Enrichment