Impact
The vulnerability is a race condition in the Linux kernel's packet socket implementation that can lead to a use‑after‑free followed by a null‑pointer dereference, resulting in a kernel panic and loss of service.
Affected Systems
All Linux kernels that expose AF_PACKET sockets and have not yet incorporated the listed security commits (1a35da325cac4d5bcad76a2aa943408a6f1d9000, 2c7b5eb87b2b288cdbde825f21d2b83b2f5da747, a08196c3cc105947746ec21309edfbb60275fcdb, ad740b4990347521f0db260d381f9f74e7b340ba, cf8189b82bb93f219ab740e0346c919ad65ada62) are affected. The advisory does not specify a version range; any kernel containing these commit hashes is considered fixed.
Risk and Exploitability
Exploitation requires local control over a packet socket, which normally requires root or CAP_NET_ADMIN; thus the likely attack vector is a local privileged attacker. The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1% signals a low probability of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog. Triggering the race condition will crash the kernel, causing a denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA