Impact
The Linux kernel contains a flaw in the ethtool tsinfo-related routine. When the preparation stage fails, the code mistakenly passes an error pointer to genlmsg_cancel, attempting to cancel a message that was never started. This null pointer dereference causes a kernel panic, resulting in an immediate denial of service as the system becomes unavailable until rebooted.
Affected Systems
All Linux kernel versions that include the generic ethtool implementation before the commit that resolved the bug are affected. The provided CPE list covers every Linux kernel release and the 7.1 release candidates (rc1‑rc5). Consequently, any system running a kernel prior to the patch that contains this path is vulnerable when a user invokes ethtool to query tsinfo on a network device.
Risk and Exploitability
The flaw is exploitable by triggering a failing ethtool tsinfo call, which typically requires local execution of the ethtool utility or sufficient privileges to run it. The CVSS score of 5.5 indicates a medium severity. The EPSS score of less than 1 % denotes a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers who can invoke ethtool locally will cause a kernel crash, leading to a denial of service until the system is rebooted.
OpenCVE Enrichment
Ubuntu USN