Impact
Unrecoverable packet fragments in the Linux kernel cause netfilter modules such as xt_u32, nfnetlink_queue, and nfnetlink_log to incorrectly handle packet data or to bail out with errors. The flaw may result in valid traffic being dropped or, in worst‑case scenarios, lead to kernel instability. The weakness lies in improper handling of unreadable skb fragments and is reflected by CWE‑390.
Affected Systems
All Linux kernel installations that include the netfilter framework, in particular attachments that employ the xt_u32, nfnetlink_queue, or nfnetlink_log modules, are potentially affected. No specific version ranges were disclosed, so any kernel that incorporates the buggy code before the referenced patch is at risk.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, a remote attacker able to craft network traffic with unreadable fragments could trigger the defect, leading to service disruption. Because the issue is in kernel‑level packet processing, the potential impact is high, but real‑world exploitation is deemed unlikely.
OpenCVE Enrichment
Debian DLA