In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
Whenever codel drops packets during peek, it calls
qdisc_tree_reduce_backlog. An issue arises because it calls
qdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops
to zero, but peek returns an skb, the parent's qlen_notify callback will
be executed even though codel still has 1 packet on the queue and, thus,
will mistakenly deactivate the parent's class causing issues like a wild
memory access when qfq has codel as a child:
[ 36.339843][ T370] Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI
[ 36.340408][ T370] KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127]
[ 36.340737][ T370] CPU: 2 UID: 0 PID: 370 Comm: tc Not tainted 7.1.0-rc5-00287-g66e13b626592 #87 PREEMPT(full)
[ 36.341113][ T370] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011
[ 36.341357][ T370] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:1029 (discriminator 2) include/linux/list.h:1043 (discriminator 2) net/sched/sch_qfq.c:1369 (discriminator 2) net/sched/sch_qfq.c:1395 (discriminator 2)) sch_qfq
[ 36.342221][ T370] RSP: 0018:ffff8881100ef370 EFLAGS: 00010216
[ 36.342422][ T370] RAX: 0000000000000000 RBX: ffff8881058a9568 RCX: dffffc0000000000
[ 36.342664][ T370] RDX: 1ffff11021064dc3 RSI: ffff888108326e00 RDI: dffffc0000000000
[ 36.342905][ T370] RBP: ffff8881058a8280 R08: dead000000000122 R09: 1bd5a00000000024
[ 36.343140][ T370] R10: fffffbfff2940329 R11: fffffbfff2940329 R12: 0000000000000000
[ 36.343383][ T370] R13: dead000000000100 R14: ffff8881058a9580 R15: ffff8881058a9578
[ 36.343631][ T370] FS: 00007fc04b0ca780(0000) GS:ffff888184fef000(0000) knlGS:0000000000000000
[ 36.343911][ T370] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 36.344116][ T370] CR2: 0000557c02c02000 CR3: 000000010e0ba000 CR4: 0000000000750ef0
[ 36.344359][ T370] PKRU: 55555554
[ 36.344481][ T370] Call Trace:
...
[ 36.345054][ T370] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1487) sch_qfq
[ 36.345222][ T370] qdisc_reset (net/sched/sch_generic.c:1057)
[ 36.345503][ T370] __qdisc_destroy (net/sched/sch_generic.c:1096)
[ 36.345677][ T370] qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)
[ 36.346335][ T370] tc_get_qdisc (net/sched/sch_api.c:1528 net/sched/sch_api.c:1556)
Fix this by only calling qdisc_tree_reduce_backlog in peek after the
qlen is restored.
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
AV:N - Remote senders reach the bug when packets traverse a QFQ (or other qlen_notify parent) with a codel child: qfq_enqueue() and qfq_dequeue() call the child peek handler during __dev_queue_xmit scheduling, and CoDel can drop there before qlen is restored.
AC:L - The attacker controls traffic rate, packet size, and CoDel drop behavior to force drops during peek while qlen reads zero; this is a deterministic logic bug, not a race on uncontrollable kernel state or a rare compile-time configuration.
PR:N - On systems where an operator has already deployed a parent qdisc with a codel child, any remote party that can send packets into the shaped class can trigger the faulty peek/drop path with no account or capabilities on the victim host.
UI:N - Exploitation requires only attacker-generated traffic (and, for full crash during teardown, attacker-initiated tc reconfiguration); no independent action by another user or administrator is needed at trigger time.
S:U - The flaw corrupts in-kernel QFQ/CoDel scheduler structures and memory within the same kernel security domain; it does not cross VM, container, or IOMMU authority boundaries.
C:H - False qlen_notify prematurely deactivates QFQ aggregates while packets remain; the fix commit shows KASAN wild-memory-access on poisoned aggregate list nodes in qfq_deactivate_agg(), giving attacker-influenced reads from freed/corrupted scheduler memory.
I:H - Corrupted aggregate/class linkage leads to invalid hlist operations and inconsistent scheduler state that can be steered with heap layout control, yielding memory corruption primitives usable for arbitrary kernel writes or control-flow hijack.
A:H - The published oops is a general protection fault from corrupted QFQ state during qdisc teardown, and the same corruption during live packet scheduling can reliably kernel-panic or hang affected hosts.
| Attack Vector |
Network |
Scope |
Unchanged |
| Attack Complexity |
Low |
Confidentiality Impact |
High |
| Privileges Required |
None |
Integrity Impact |
High |
| User Interaction |
None |
Availability Impact |
High |
AV:N - Remote senders reach the bug when packets traverse a QFQ (or other qlen_notify parent) with a codel child: qfq_enqueue() and qfq_dequeue() call the child peek handler during __dev_queue_xmit scheduling, and CoDel can drop there before qlen is restored.
AC:L - The attacker controls traffic rate, packet size, and CoDel drop behavior to force drops during peek while qlen reads zero; this is a deterministic logic bug, not a race on uncontrollable kernel state or a rare compile-time configuration.
PR:N - On systems where an operator has already deployed a parent qdisc with a codel child, any remote party that can send packets into the shaped class can trigger the faulty peek/drop path with no account or capabilities on the victim host.
UI:N - Exploitation requires only attacker-generated traffic (and, for full crash during teardown, attacker-initiated tc reconfiguration); no independent action by another user or administrator is needed at trigger time.
S:U - The flaw corrupts in-kernel QFQ/CoDel scheduler structures and memory within the same kernel security domain; it does not cross VM, container, or IOMMU authority boundaries.
C:H - False qlen_notify prematurely deactivates QFQ aggregates while packets remain; the fix commit shows KASAN wild-memory-access on poisoned aggregate list nodes in qfq_deactivate_agg(), giving attacker-influenced reads from freed/corrupted scheduler memory.
I:H - Corrupted aggregate/class linkage leads to invalid hlist operations and inconsistent scheduler state that can be steered with heap layout control, yielding memory corruption primitives usable for arbitrary kernel writes or control-flow hijack.
A:H - The published oops is a general protection fault from corrupted QFQ state during qdisc teardown, and the same corruption during live packet scheduling can reliably kernel-panic or hang affected hosts.
CVSS 3.1