Impact
In the Linux kernel's AFS module an out‑of‑band rxrpc message handler was not properly cancelled when a cancellation request was issued. The handler could therefore remain active and continue processing these messages, which are typically used to challenge security credentials. The unchecked processing can consume kernel resources and potentially delay or block legitimate operations, resulting in a denial of service scenario.
Affected Systems
Linux kernel distributions that include the AFS module before commit 231414253b648b3518b56f09710b831945d6a2fc are impacted. This includes all releases where the AFS module is compiled and rxrpc networking is enabled. Administrators should verify whether their operating system includes the commit or remains vulnerable using the provided reference commits.
Risk and Exploitability
No CVSS score is provided and the EPSS score is unavailable, so the formal severity is unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector, based on the description, is that an adversary must be able to send crafted out‑of‑band rxrpc messages to a target system with the AFS module active. This generally requires network connectivity or local access to the vulnerable kernel component. The impact is a potential denial of service if the condition is triggered, but no additional privilege escalation is indicated by the CVE data.
OpenCVE Enrichment