Impact
The Linux kernel contains a defect in the mlx5e driver where failure to retrieve the LAG sequence from a peer device results in an unchecked pointer dereference, causing a memory access violation and kernel panic. This flaw results in an immediate loss of service on the affected system and could allow an attacker to disrupt availability by triggering the crash under certain link‑aggregation conditions.
Affected Systems
The vulnerability affects Linux systems that use the mlx5e Ethernet driver in the kernel. No specific kernel version is listed, so any kernel build that includes the buggy code path may be susceptible until the patch is applied.
Risk and Exploitability
The CVSS score is 7.8, and the EPSS score is < 1%, but the lack of a mitigation in the CISA KEV catalog suggests no known exploitation in the wild. The kernel crash would most likely be triggered by a legitimate or malicious configuration change or event involving LAG management. While the attack vector is inferred to be through networking and driver interaction, the severity remains high due to the critical nature of kernel memory corruption.
OpenCVE Enrichment