
1/31/2023 · Frederick Lawler
What this post added
This post details the discovery and analysis of a kernel bug (CVE-2022-47929) related to Linux Traffic Control's 'noqueue' discipline when used with classful qdiscs, exacerbated by USER namespaces. Cloudflare engineers identified how this vulnerability could lead to an unprivileged denial-of-service attack and contributed a fix by disallowing 'noqueue' for qdisc classes, enhancing the security and stability of the underlying infrastructure.