Impact
A defect in the Linux kernel’s skb_tx_error() routine incorrectly clears shared zerocopy state from a sk_buff clone. This results in a cloned packet still in flight being altered, causing kernel memory corruption. In an Open vSwitch environment, packets that trigger non‑last recirculation can lead to this flaw and potentially corrupt data used for ESP decryption, giving an attacker the ability to inject malicious code or elevate privileges.
Affected Systems
All Linux kernel releases that do not contain the commit that patches the skb_tx_error() handling are affected. The vulnerability is triggered when Open vSwitch processes packets that go through a non‑last OVS_ACTION_ATTR_RECIRC action, which causes a skb_clone() to be sent into the downstream processing path without privatizing fragments.
Risk and Exploitability
The CVSS base score of 7.8 denotes high severity, yet the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, implying that no publicly available, weapon. The likely attack vector is remote network traffic sent to an Open vSwitch instance that runs on a vulnerable Linux kernel and could be exploited by sending specially crafted packets that trigger the recirculation path.
OpenCVE Enrichment
Debian DSA