Impact
The Linux TIPC subsystem contains a use‑after‑free flaw when a bearer is disabled while a receive handler still dereferences the discoverer structure. This vulnerability, identified as CWE-825, can corrupt kernel memory and, if exploited, allow an attacker to execute code with kernel privileges. The flaw is triggered during packet reception of the TIPC UDP bearer. Affected systems include any Linux kernel built with TIPC support enabled via CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP. The vulnerability can be reached from an unprivileged user namespace because the TIPCv2 generic netlink family is namespace‑ok and bearer commands lack GENL_ADMIN_PERM, giving local access to exploit attempts. The CVSS score is 7.8 and the EPSS score is below 1 %, indicating a low to moderate likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation would require the attacker to generate crafted TIPC UDP packets from within a user namespace, a scenario that is feasible for a local or compromised user with access to the system’s networking stack.
Affected Systems
Affected systems include any Linux kernel built with TIPC support enabled via CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP. The vulnerability can be reached from an unprivileged user namespace because the TIPCv2 generic netlink family is namespace‑ok and bearer commands lack GENL_ADMIN_PERM, giving local access to exploit attempts.
Risk and Exploitability
The CVSS score is 7.8 and the EPSS score is below 1 %, indicating a low to moderate likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation would require the attacker to generate crafted TIPC UDP packets from within a user namespace, a scenario that is feasible for a local or compromised user with access to the system’s networking stack.
OpenCVE Enrichment
Debian DLA
Debian DSA