Impact
The kernel networking shaper module can lose a reference to a net device between obtaining a reference and acquiring its lock, allowing a hierarchy to be created after the device has been unregistered. This race can leave the hierarchy allocated without a valid device, resulting in a lingering allocation that is never cleaned up.
Affected Systems
The vulnerability affects any Linux kernel that implements the shaper subsystem and has not incorporated the fix contained in commit 719f6784f918f9e32f3ff3b197f900e852223f9d (and the associated subsequent commits). No specific kernel releases are enumerated in the vulnerability data, so all kernels prior to the inclusion of this patch are potentially affected.
Risk and Exploitability
The CVSS score and EPSS metric are not supplied in the vulnerability report, and the issue is not listed in CISA’s KEV catalog, so the severity and likelihood of exploitation are not quantified. The patch addresses the race condition, and no explicit attack vector is documented in the payload; therefore it cannot be determined from the data whether the flaw requires local or privileged access.
OpenCVE Enrichment