Impact
The vulnerability allows non‑zero‑copy devmem TCP transmissions when the NETIF_F_SG flag is absent, causing the kernel to attempt a copy operation on an iovec that references a dmabuf. This can lead to copy failures or violate internal invariants that separate readable and unreadable fragments, potentially resulting in memory corruption or kernel instability. The issue stems from a weakness in input validation (CWE-20). The patch tightens parameter validation to reject devmem traffic that does not meet zero‑copy requirements, thereby restoring the intended separation of network fragments.
Affected Systems
All Linux kernel releases that include the tcp devmem handling code prior to the patch; the issue is present in any kernel built from the source specified in the referenced commits and does not affect other kernel subsystems. It impacts network interfaces that may use devmem bindings and the NETIF_F_SG flag.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score of less than 1% and lack of listing in the CISA KEV catalog suggest a very low likelihood of exploitation. However, if an attacker can craft packets that trigger non‑zero‑copy devmem outbound traffic—either through local privilege or remote network connections—they could destabilize the kernel or corrupt data buffers. The attack vector is inferred to be network‑based, requiring the ability to send large or specially formatted TCP segments that invoke the devmem path.
OpenCVE Enrichment