Impact
The Linux kernel Thunderbolt networking subsystem can allocate a HopID for XDomain connections and, if the requested identifier does not match the expected value, the ID is never released. This causes a permanent reservation of a finite resource. Repeated allocation failures over time exhaust the HopID pool, preventing new XDomain connections from being established and effectively disrupting network operations.
Affected Systems
All Linux kernel distributions where the Thunderbolt networking module is loaded. The vulnerability resides at the kernel level, affecting any distribution that ships with this code without the subsequent patch.
Risk and Exploitability
The CVSS score of 4.8 classifies the issue as moderate severity, and the EPSS score of less than one percent indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to initiate repeated Thunderbolt XDomain connections to the target system. The precise attack vector is not specified in the data, but it can be inferred that it is limited to environments where Thunderbolt networking is active and potentially exposed to attackers.
OpenCVE Enrichment
Debian DSA