Impact
The vulnerability is a contract violation in the Linux kernel component ntb_transport_tx_enqueue, where a commit intended to drop packets when a QP link is down incorrectly returns 0 instead of an error code. Returning zero signals success to the caller, causing ntb_netdev to report NETDEV_TX_OK while the packet is neither queued nor freed. As a result, each transmit operation that runs while the link is down leaks a socket buffer (skb), gradually exhausting kernel memory.
Affected Systems
All Linux distributions that ship the kernel without the f195a1a6fe41 commit are affected, regardless of distribution or patch level. The specific versions are not listed, so any kernel that predates the patch that restored the proper error return is considered vulnerable.
Risk and Exploitability
Based on the description, the most likely attack vector is local packet transmission to trigger the condition, as the function is invoked during normal network operations. An adversary could generate network traffic that races with a manual or automated link reset to cause repeated skb leaks. The moderate CVSS score of 4.1, combined with an EPSS score of less than 1% and absence from the CISA KEV catalog, suggests that active exploitation is unlikely, but a determined attacker could force resource exhaustion by repeatedly provoking the failure.
OpenCVE Enrichment
Debian DSA