Impact
The Linux kernel's bridge Multi–Chassis Link Aggregation (MRP) test frame generation was found to leave three bytes uninitialized in the sub–option TLV header and alignment padding. These bytes are transmitted over the network, potentially leaking random data from the kernel's memory. The flaw is an information–disclosure vulnerability that does not provide code execution, denial of service, or privilege escalation.
Affected Systems
All Linux kernel versions that have the bridge MRP feature enabled and that were released before the commit that zeroes the TLV header and alignment bytes are affected. The exact version range is not specified; operators should assume that any kernel prior to the referenced patch holds this flaw and should upgrade to a kernel that includes the fix.
Risk and Exploitability
Exploitation requires an attacker to observe outgoing MRP test frames on a network that the host can transmit to, as the uninitialized bytes are sent over the wire. The likely attack vector is a remote network attacker who can capture these frames. Data leakage could expose arbitrary memory contents from the kernel, potentially aiding further attacks, but it cannot be used to gain code execution, cause denial of service, or elevate privileges. The EPSS score is low (<1%) and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation remains uncertain, yet it should be addressed in sensitive environments.
OpenCVE Enrichment
Debian DLA
Debian DSA