Impact
A NULL pointer dereference occurs in the idpf driver when RSS lookup tables are accessed before the network interface is brought up. The missing initialization leads to a kernel panic during early ethtool operations such as turning rxhash on or off. This crash results in a loss of kernel availability and can disrupt services running on the affected host. The weakness is a NULL pointer dereference (CWE‑476).
Affected Systems
All systems running the Linux kernel with the idpf driver, including releases such as 6.19 (alpha, beta, and release candidate builds) and earlier kernel versions where the idpf driver is present. The CPEs indicate applicability to the broad Linux kernel family.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity; the EPSS score is below 1 %, indicating a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user able to invoke ethtool commands on a down interface, so the likely attack vector is local. If an attacker can perform these operations before the interface is activated, they can cause a kernel panic and deny service.
OpenCVE Enrichment
Debian DSA