Impact
The vulnerability lies in the Linux kernel’s ESP handling. During fast‑path processing, a check that ensures the combined length of the packet trailer and payload does not exceed a page is omitted. An attacker that can supply crafted ESP packets may cause memory corruption due to improper allocation, potentially leading to privilege escalation or a denial of service. The flaw is associated with CWE‑770.
Affected Systems
All Linux kernel releases are affected until the kernel incorporates the patch that restores the combined‑length gate. Any system running a vulnerable kernel is at risk, irrespective of vendor or version.
Risk and Exploitability
The flaw has a CVSS score of 9.8 and an EPSS score of less than 1 %. Although exploitation is unlikely under normal conditions, the impact is severe and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network‑based, requiring the ability to forge or inject ESP packets toward the target. Successful exploitation would allow privilege escalation or complete control of the affected host.
OpenCVE Enrichment
Ubuntu USN