Impact
The Linux kernel rmnet driver had a bug where sub‑frames created by rmnet_map_deaggregate() lacked a device assignment. When a MAP command frame was processed, the code attempted to lock the device that remained NULL, causing a null‑pointer dereference that led to a fatal kernel panic. The fault consumes only four bytes and terminates the system, disrupting all network services. The vulnerability is limited to a denial of service; there is no evidence of code execution.
Affected Systems
Affected systems are Linux kernel installations that include the rmnet driver without the recent commit that restores skb->dev. The CVE description does not list specific kernel versions, so any kernel running before the fix may be vulnerable.
Risk and Exploitability
The EPSS score of < 1% suggests a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild. The exploit chain requires an unprivileged local user to unshare a user+net namespace, create an rmnet link over a TAP device configured with INGRESS_DEAGGREGATION and INGRESS_MAP_COMMANDS, and inject an aggregated frame carrying a flow‑control command. Based on the description, it is inferred that the attacker must have local access and the ability to write to the TAP device, as well as a kernel compiled with the rmnet driver. Once triggered, the null‑pointer dereference causes a kernel panic, denying all network services on the affected host.
OpenCVE Enrichment
Debian DLA
Debian DSA