Impact
The vulnerability occurs when the kernel processes IPv4 or IPv6 multicast packets that are not locally deliverable. A socket is prefetched via BPF or UDP early demultiplexing, but a reference to that socket is not held. If the socket is destroyed before the packet is forwarded, the stale skb->sk is dereferenced, causing a use‑after‑free (CWE‑825) that results in a kernel crash.
Affected Systems
All Linux kernel releases that contain the multicast forwarding logic with the buggy reference handling are affected. The cpe indicates all Linux kernel packages, and no specific version range is identified in the CVE record, so any kernel that has not incorporated the official fix is at risk.
Risk and Exploitability
The CVSS score of 7.8 categorises this flaw as high severity. The EPSS score below 1% indicates a low probability of exploitation at this time, and the vulnerability is not present in the CISA KEV catalog. An attacker would need to send crafted multicast traffic to a vulnerable interface; because the flaw manifests only when the prefetched socket is destroyed beforehand, successful exploitation may require precise timing, it more difficult to achieve. Nevertheless, the potential impact of a kernel crash and a possible denial of service justifies prompt remediation.
OpenCVE Enrichment
Debian DSA