Impact
The vulnerability involves a defect in the Linux kernel’s Open vSwitch component. When a packet is subject to a flow key update during connection tracking, a failure can lead to the packet buffer (skb) being leaked because the error handling path does not free the skb as it should. The result is a memory leak that can incrementally consume kernel memory, potentially degrading system stability or leading to out‑of‑memory conditions. The weakness involves improper resource management during error handling.
Affected Systems
The affected software is the Linux kernel, specifically the Open vSwitch implementation. The patch is supplied to Linux kernel maintainers (not tied to a specific distribution version in the data presented). Users running recent kernel versions that incorporated the reported change, or those able to upgrade to a newer kernel release that includes the fix, will be protected. Versions prior to the patch are vulnerable. No vendor‑specific product versions are listed beyond the generic Linux kernel.
Risk and Exploitability
The vulnerability is considered unlikely to be triggered because it requires a specific packet unparseability condition during an action chain on previously valid packets. No exploit code has been published, and the EPSS score is < 1%, indicating low known exploitation probability. It is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Nevertheless, an attacker who can craft traffic that triggers the failure could cause a memory leak, potentially affecting system availability. The CVSS score is 5.5, indicating moderate severity. The impact is limited to memory consumption rather than direct remote code execution or privilege escalation.
OpenCVE Enrichment
Debian DSA