Impact
In the Linux kernel, the octeontx2-pf driver contains a flaw that allocates a send‑queue timestamp ring buffer but never frees it when the interface is torn down or the device is removed. The buffer therefore remains resident in kernel memory and can retain sensitive packet timing information. Any process with root privileges can potentially read this leaked memory, compromising confidentiality of kernel data. This vulnerability is a classic memory‑leak weakness.
Affected Systems
The affected products are Linux kernels that incorporate the octeontx2-pf network driver, used on OCTEON TX2 system‑on‑chip platforms. Specific kernel versions are not listed in the CVE data, indicating that older releases containing the unpatched driver fall under the impacted set.
Risk and Exploitability
The EPSS score for this issue is not available and it is not listed in the CISA KEV catalog, implying no current exploitation reports. Although the CVSS score is not supplied, memory‑leak vulnerabilities that expose kernel data generally receive high severity ratings. The likely attack vector is local, requiring an attacker to attain root or elevated privileges to read the leaked memory. The overall risk is moderate pending patch application.
OpenCVE Enrichment