Impact
A logic error in the octeontx2-af driver of the Linux kernel allows a Virtual Function (VF) to inadvertently clear the Physical Function (PF)’s promiscuous and all‑multicast entries when the VF brings its interface up or down with both flags set to false. This results in the PF losing its normal traffic handling capabilities and can disrupt or interrupt network traffic for the host.
Affected Systems
The issue affects Linux kernel builds that include the octeontx2-af component. Any kernel containing the unpatched octeontx2-af driver is potentially vulnerable, regardless of the specific release version.
Risk and Exploitability
The CVSS score is 7.9 and the EPSS score is < 1%, indicating a high severity but a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker who can control VF configuration—either through local privileged access or by compromising a VM that can manipulate VF settings—could trigger the bug and cause the PF to lose its promiscuous and all‑multicast state, thereby degrading or denying network service.
OpenCVE Enrichment