Impact
The Linux kernel Thunderbolt driver mishandles the teardown of DMA paths and ring buffers, stopping the rings before disabling high‑speed DMA paths. This causes packet descriptors to become invalid while frames are still in flight, leading to repeated pending‑bit timeouts. On affected hardware the link can crash and require a host power cycle, effectively disrupting device operation. The weakness is a resource‑management error that prevents proper cleanup of active data paths.
Affected Systems
All releases of the Linux kernel that include the Thunderbolt network driver without the patched teardown order are affected, including the stock kernel 6.17 tree and earlier. The vulnerability resides in the generic kernel source and does not depend on a vendor‑specific build; any machine running an unpatched kernel and using a Thunderbolt network interface is potentially impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, suggesting the likelihood of exploitation is low. The attack requires privileged kernel access or the ability to repeatedly bring a Thunderbolt link up and down, which is typically a local or physical attack scenario. If exploited, the attacker can bring the host or the Thunderbolt network device into a degraded state, causing denial of service for critical communications.
OpenCVE Enrichment
Debian DLA
Debian DSA