Impact
The Linux kernel netfilter flowtable contains logic that configures tunnel routes using the wrong packet direction. As a result, traffic traversing a tunnel is forwarded to an unintended interface or network segment. The vulnerability does not provide an attacker with code execution, privilege escalation, or data disclosure, but it can cause connectivity failures or inadvertent exposure of traffic to networks where it should not appear.
Affected Systems
All Linux kernel builds that include the netfilter flowtable component, whether from mainline sources or distribution kernels, are affected. This includes mainstream distributions and custom kernels that enable flowtable for either Layer‑2 or Layer‑3 tunneling. No specific version information is available.
Risk and Exploitability
The EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation is unlikely and no public attacks are known. Based on the description, it is inferred that an attacker would need to generate traffic that exercises the vulnerable flowtable state transition—such as a crafted packet routed through a tunnel or a configuration that forces a tunnel‑based route lookup—to trigger the mis‑routing. Because the issue only misroutes traffic rather than executing arbitrary code, the overall risk is considered low, though the potential for network disruption makes rapid remediation advisable.
OpenCVE Enrichment