Impact
The vulnerability involves a data race in vlan_transfer_features that changes dev->hard_header_len without appropriate locking when toggling hardware VLAN offload. Lockless transmission paths then reserve insufficient headroom, causing skb_under_panic in functions such as packet_snd and ip6_finish_output2. The unchecked mismatch between allocated headroom and header creation can also lead to erroneous header insertion. The effect is a kernel panic, resulting in service interruption and denial of service.
Affected Systems
All releases of the Linux kernel that have not incorporated the backport commits e16e960d55a4 and cef51860becd. The problem emerges on any interface where NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX can be toggled, regardless of the underlying hardware type.
Risk and Exploitability
No CVSS score is provided, but the patch mitigates a race condition that leads to a fatal exception; the consequence is a systemic crash rather than data leakage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation would likely require privileged access to modify offload settings on the target system, making local or highly privileged remote attack vectors the most plausible. While the exact likelihood of exploitation cannot be quantified, the crash potential warrants immediate attention.
OpenCVE Enrichment
Debian DSA