Impact
The bug occurs when an outbound IPsec policy contains an optional IPTFS template that is not rejected by the kernel. The kernel performs a stack‑out‑of‑bounds read in xfrm_state_find, allowing an attacker to read memory beyond the array bounds. The resulting vulnerability is a classic out‑of‑bounds read that can lead to information disclosure or a kernel fault, categorised as CWE‑125.
Affected Systems
The vulnerability affects the Linux kernel. All Linux distributions whose kernel has not incorporated the patch that rejects optional IPTFS templates in outbound policies are affected. Specific version information is not listed in the data, so any kernel version that allows optional IPTFS in outbound policies is potentially vulnerable until the fix is applied.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate exploitation likelihood, but the exact CVSS score is not provided. The attack likely requires privileged capability to create an XFRM policy, suggesting the vector is local or requires elevated privileges. If exploited, an attacker could gain kernel memory disclosure or cause a denial of service by triggering a crash, but there is no direct evidence of remote code execution or other privileged escalation.
OpenCVE Enrichment