PT-2025-43128 · Linux+1 · Linux Kernel+1

Published

2023-08-31

·

Updated

2025-11-28

·

CVE-2023-53727

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.5.0-syzkaller-00453-g727dbda16b83
Description The Linux kernel contains an issue within the networking scheduler related to the fq pie (Fair Queueing Packet Identifier) implementation. Specifically, the fq pie timer() function can experience stalls when handling a large number of flows, up to the limit of 65536. This occurs because the function consumes excessive time during processing, as reported by syzbot. The issue is addressed by adding logic to yield the CPU every 2048 flows, reducing the time spent in the function and preventing blocking of qdisc fast paths. In the worst-case scenario (65536 flows), the complete scan would require 31 jiffies. The root cause is related to resource contention and inefficient CPU usage within the fq pie timer() function.
Recommendations Versions prior to 6.5.0-syzkaller-00453-g727dbda16b83 should be updated to a newer version that includes the fix.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03870
CVE-2023-53727
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1

Affected Products

Linux Kernel
Suse