Impact
The vulnerability is a use‑after‑free in the Linux kernel Open VSwitch code. When a flow table entry is deleted, the mask pointer is freed via RCU, yet the deletion path still accesses that pointer before proper RCU synchronization. This race can lead to a kernel crash. Based on the reported kernel crash, it is inferred that the fault does not expose sensitive data. The resulting crash terminates the kernel, causing a denial‑of‑service flaw (CWE‑825).
Affected Systems
Affected systems are Linux kernel releases that include the Open VSwitch module with legacy flow deletion logic. The kernel version range is not specified in the advisory, so any kernel that implements the unpatched flow‑deletion path is potentially vulnerable. Systems running the module appear on any Linux platform that ships with Open VSwitch support.
Risk and Exploitability
The CVSS score of 7.8 indicates medium‑high severity, while the EPSS score of <1% points to a low probability of exploitation in the wild. The issue is not listed in CISA's KEV catalog. Exploitation issuing a flow‑deletion netlink command during the RCU grace period. The likely attack vector is via the Open VSwitch netlink interface; if this interface is exposed to untrusted networks, remote exploitation becomes possible—this inference is based on the description’s mention of netlink commands and the absence of network restrictions.
OpenCVE Enrichment
Debian DSA