Impact
The Linux kernel thunderbolt networking driver contains a flaw. When establishing a connection fails, the flag that indicates a login request has been sent is not reset, leading the tear‑down routine to operate on resources that are already released. This condition triggers a dev_WARN that escalates to a kernel panic under panic_on_warn. The driver also frees a remote transmit path it never owned, silently corrupting memory that may still be in use by other subsystems. The result is a kernel crash or subtle memory corruption that could otherwise facilitate further exploitation.
Affected Systems
All Linux kernel builds that include the thunderbolt networking driver prior to the patch that clears the login_sent flag on failure paths. This includes many distribution kernels and custom builds that ship an older thunderbolt driver. No specific release range is listed, so any kernel version that contains the unpatched code can be affected.
Risk and Exploitability
The CVSS score of 8.8 highlights high severity, while the EPSS score of <1% signals extremely low current exploitation likelihood. The vulnerability is not present in CISA's KEV catalog. An attacker would normally require local or privileged access to trigger thunderbolt connections, and the crash is deterministic once the fault condition is met. The low EPSS suggests that exploitation is unlikely at present, but the high severity warrants prompt remediation.
OpenCVE Enrichment
Debian DSA