Impact
A null pointer dereference occurs in the Linux kernel’s SMC Datagram (SMC-D) teardown routine when the socket close sequence accesses a cleared send‑buffer descriptor, causing an uncaught fault and a kernel panic. The flaw is triggered during normal socket closure, and it does not require any special payload – the kernel crash results in a loss of availability of the entire system.
Affected Systems
All Linux kernels that compile and enable the SMC Datagram module are susceptible, unless they have applied the commit that introduces a guard for the send‑buffer descriptor. Version information is not explicitly enumerated in the advisory, so any configuration lacking the fix is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog and no public exploits have been reported. The likely attack path requires an attacker to orchestrate a socket close while the send‑buffer descriptor is cleared, a non‑trivial condition that makes practical exploitation unlikely today.
OpenCVE Enrichment
Debian DSA