Impact
This vulnerability arises in the Linux kernel’s Open vSwitch integration when an update request with a mismatched UFID causes a reply buffer to be preallocated based on the request identifier size instead of the full key‑identified flow size. The kernel then overwrites this undersized buffer, triggering a BUG_ON and resulting in a kernel panic. The flaw is a buffer overflow caused by incorrect size handling (CWE-131). If an attacker can send a crafted Open vSwitch update command, they can force the kernel to crash, leading to service disruption.
Affected Systems
Any Linux distribution that includes the Open vSwitch kernel module is potentially affected. The vendor data lists "Linux:Linux" and the CPE indicates a generic Linux kernel, so the vulnerability applies to all kernel versions that have not yet incorporated the upstream patch referenced in the commit history links. No explicit version range is specified, so users should verify whether their kernel revisions precede the commit identifiers in the advisory.
Risk and Exploitability
The EPSS score of < 1% indicates a very low but measurable probability of exploitation in the wild. The CVSS score of 5.5 reflects moderate severity, meaning the flaw could cause a denial of service but is not considered high‑impact. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited observed exploitation. Attackers with network access to Open vSwitch management channels can craft an update command to trigger the BUG_ON, leading to a kernel crash. Based on the description, the likely attack vector is remote exploitation via Open vSwitch control protocols.
OpenCVE Enrichment
Debian DLA
Debian DSA