Impact
An oversized transmit buffer sent through the NTB transport driver is mishandled by ntb_process_tx(): it passes a NULL data pointer to the handler and reports success, causing the associated socket buffer (skb) to remain allocated. Each instance of this bug leaks the skb, incrementally draining kernel memory. Over time a repeated injection of oversized buffers can exhaust memory, potentially leading to a kernel panic or forced reboot, thereby denying service to legitimate users.
Affected Systems
All Linux kernel builds that compile the NTB transport layer are vulnerable until the change that rejects oversized buffers in ntb_transport_tx_enqueue() is present. The description does not list specific distributions; based on the information, any distribution that ships the ntb module in its kernel, whether Debian, Red Hat, SUSE, or custom builds, is affected until a kernel update includes the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, yet the EPSS score is below 1 %, implying a very low exploitation probability. The likely attack vector requires local privileged access to the NTB driver to send oversized transmit buffers; remote exploitation or privilege escalation is not indicated in the description. Consequently, the risk profile is that of a memory‑exhaustion denial‑of‑service attack that has not been catalogued in CISA KEV.
OpenCVE Enrichment
Debian DSA