Impact
The Linux kernel includes a commit that validates the size of launch‑time metadata registered via the XSK API. Prior to this patch, metadata could be smaller than the full struct, causing the kernel to process incomplete information. This may lead to inconsistent request handling and unpredictable outcomes in the generic transmit path, potentially affecting network reliability.
Affected Systems
All Linux kernel builds that lack the commit introducing metadata size validation are vulnerable. Systems running older kernels on any distribution, whether embedded or general‑purpose, are affected until the fix is applied.
Risk and Exploitability
The high CVSS score of 7.8 reflects the potential impact of this flaw. The EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. No specific attack vector or privilege requirement is detailed in the description, so the risk level remains tied to the inherent severity of the flaw.
OpenCVE Enrichment