Impact
The vulnerability arises in the Linux kernel's xdp which copies an AF_XDP packet into an order‑0 page while advertising a frame size of PAGE_SIZE. Because the skb_shared_info tail is not omitted and the frame headroom is zero, the cloned packet can overlap or extend beyond the allocated page, leading to an out‑of‑bounds write during GRO packet processing. This memory corruption can trigger a KASAN error and ultimately cause a kernel panic, rendering the system unavailable.
Affected Systems
The flaw affects all Linux kernel releases that included the buggy implementation of xdp_convert_zc_to_xdp_frame prior to the patch commits referenced. In particular, any kernel before the fixes introduced at commit 6de17275b3ccdf9887568b07e54da2e3597217cf (and earlier commits such as 15d1f3c0dbe7a740f779337deb39f23cd8d002c8) is vulnerable. All architectures that support cpumap impacted.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is considered critical. The EPSS score of < 1 % indicates a low current exploitation probability, and the feature is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious AF_XDP packet sent through cpumap to a kernel module that processes such packets. An attacker who can inject crafted data into a vulnerable AF_XDP socket may trigger the out‑of‑bounds write, potentially bringing the kernel to a halt. Local privilege escalation or local users who can open AF_XDP sockets are sufficient namespaces further widens the attack surface.
OpenCVE Enrichment
Debian DSA