Impact
A use‑after‑free flaw in the Linux kernel’s Open vSwitch CT limit handling allows an unprivileged user to torn down. The flaw occurs when packet processing still resulting in a slab-use‑after‑free in ovs_ct_execute(). This kernel memory corruption could enable arbitrary code execution at the kernel level, as it forms a classic use‑after‑free defect tied to CWE‑825.
Affected Systems
All Linux kernel versions that contain the Open vSwitch implementation are affected, regardless of distribution. The vulnerability exists in the kernel’s networking subsystem, so any system running a susceptible kernel variant that uses Open vSwitch may be vulnerable if it allows unprivileged users to create or manipulate network namespaces.
Risk and Exploitability
The problem is a kernel flaw with a CVSS score of 7.8, indicating a high severity. An unprivileged user within a a netlink request that causes the relevant namespace to be torn down while traffic is still being processed. The EPSS score is < 1 %, implying a low probability of exploitation, and the vulnerability is not listed in CISA KEV, meaning no known active exploitation is documented. The likely attack vector is local, requiring no elevated privileges and no network connectivity.
OpenCVE Enrichment
Debian DSA