Impact
The Linux kernel’s smc_rx_splice routine previously passed page references to splice_to_pipe before ensuring that those references were retained, causing a refcount imbalance that can underflow page refcounts and lead to a use‑after‑free state. This flaw may result in unintended kernel memory access or instability.
Affected Systems
All Linux kernel installations for which the smc_rx_splice function is compiled and in use prior to the commit that adds the safety checks. The fix is present in newer kernel releases, but the specific version range is not listed in the advisory.
Risk and Exploitability
The CVSS score of 8.4 classifies this issue as high severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in KEV, meaning no publicly known exploitation to date. The likely attack vector is a remote network attacker targeting the SMC networking path, but this is inferred because the advisory does not explicitly state the vector. A use‑after‑free in the kernel can destabilize the system, so immediate patching is recommended to mitigate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA