Impact
An unprivileged user in a user namespace can craft an SRv6 packet that includes a Hop‑by‑Hop and Destination Options outer extension headers, followed by an SRH and a minimal inner IPv6 packet. During decapsulation, the outer extensions leave a large offset in the IPv6 control block that remains set when the inner packet is processed. This stale offset causes the kernel to read beyond the packet data, resulting in a KASAN out‑of‑bounds error. The out‑of‑bounds read corrupts kernel memory and may lead to a denial of service or, if exploited further, to privilege escalation.
Affected Systems
The flaw exists in the Linux kernel. All releases that have not incorporated the commit that resets the IPv6 control block after decapsulation are affected. No specific version list is provided, so any kernel that still uses the old logic is vulnerable.
Risk and Exploitability
The CVSS score is 9.8, the EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not listed in CISA KEV. The flaw can be exploited by an unprivileged user through crafted network packets, resulting in a critical risk that may cause kernel crashes and potentially grant privilege escalation if memory can be manipulated.
OpenCVE Enrichment
Debian DSA