Impact
The kernel helper skb_zerocopy() copies data from one socket buffer to another. If the fragment copy fails, the helper mistakenly calls skb_tx_error() on the original buffer, destroying it and clearing the SKBFL_SHARED_FRAG flag. This out‑of‑scope free results in a Use‑After‑Free condition (CWE‑416). In paths utilized by Open vSwitch, the packet is not immediately dropped, which causes subsequent processing to reference the freed buffer. That can lead to memory corruption, enabling an attacker to execute code or cause denial of service through carefully crafted network traffic that triggers the fragment copy failure.
Affected Systems
All versions of the Linux kernel shipped before the patch are affected, including any installation that uses Open vSwitch in the OVS_ACTION_ATTR_USERSPACE path. The specific patch commits referenced in the advisory remove the skb_tx_error call from skb_zerocopy() and should be applied to secure the system.
Risk and Exploitability
The CVSS score of 9.3 reflects a high‑severity risk of remote code execution or privilege escalation. The EPSS score of <1% indicates a low probability of exploitation in the wild at the time of assessment, but the impact remains severe and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to craft network traffic that triggers a fragment copy failure in the kernel, for example by sending malformed packets to a host running Open vSwitch. Based on the description, the likely attack vector is network‑bound through the kernel’s packet processing path; the probability of successful exploitation remains low, but the potential damage is significant.
OpenCVE Enrichment
Debian DLA
Debian DSA