Impact
This vulnerability is a use‑after‑free bug in the Linux kernel’s MPLS forwarding code. After advancing the packet head to read the inner Ethernet/IP header, the code reuses a stale pointer to the packet header because the skb head was replaced by pskb_expand_head. Dereferencing that pointer triggers a KASAN error and can lead to a kernel crash or denial of service. The flaw is a classic example of Memory Management During Allocation or Reallocation weakness (CWE‑825).
Affected Systems
The issue resides in the Linux kernel’s MPLS forwarding path. Any kernel release that has not yet incorporated the commit fixing mpls_select_multipath is vulnerable. The affected vendor is Linux, and the product is the Linux kernel. No specific version range is provided; therefore all installations prior to the patch are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score of less than 1% suggests a very low but nonzero likelihood of exploitation in the wild. Based on the description, it is inferred that a remote attacker who can inject a specially crafted MPLS‑encoded Geneve packet into a bareudp/MPLS multipath configuration can trigger the vulnerable code path. The attacker only needs network access; local privileges are not required. No publicly documented exploits exist, and the flaw is not listed in CISA’s KEV catalog, but a well‑crafted packet would cause a kernel crash and result in denial of service.
OpenCVE Enrichment
Debian DSA