Impact
ecryptfs_parse_tag_70_packet subtracts fixed metadata fields from the packet. A malformed packet whose body is smaller than those fixed fields causes an unsigned integer underflow, potentially leading the kernel to read or write memory outside the intended bounds. The resulting kernel fault would crash the system, causing a denial of service. This weakness is an instance of integer underflow (CWE-191). All Linux distributions that ship an unpatched kernel and enable ecryptfs—whether through user mounts or kernel modules—could be affected. No specific kernel release is listed in the CNA data, so any kernel version that has not yet incorporated the fix may be vulnerable.
Affected Systems
All versions of the Linux kernel that include the ecryptfs module and have not yet applied the patch are affected. This includes every mainstream distribution that ships the kernel without the recent ecryptfs packet validation fix, regardless of distribution. The exact impacted kernel releases are not specified in the CNA data, so any kernel prior to the fix is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 represents a high severity vulnerability. The EPSS score of <1% indicates an extremely low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting limited current exploitation activity. The likely attack vector is remote or local delivery of a crafted ecryptfs packet to a system that accepts ecryptfs data, as inferred from the kernel’s parsing routine. An attacker who can supply such a packet could trigger a crash and disrupt service, although this does not lead to code execution or data disclosure.
OpenCVE Enrichment
Debian DSA