Impact
A flaw in the Linux kernel’s TCP implementation causes urgent pointer values to be incorrectly copied during retransmission. The retransmit path ignores the guard that the normal path uses when urgent mode is active, allowing a multi‑segment packet to be built with a single urgent pointer that is offset relative to each segment’s sequence number. The receiver then interprets this malformed urgent pointer as a moving point of interest, effectively treating real urgent data as ordinary in‑band data. The consequence is corruption of the data stream, which can lead to application failures, protocol mismatch, and potential exploitation of downstream services that depend on correct urgent data handling. The bug does not provide arbitrary code execution or privilege escalation, but it does weaken data integrity and could serve as a foothold for more complex attacks if combined with other weaknesses.
Affected Systems
The vulnerability impacts all Linux kernel installations that use the standard TCP stack and have not incorporated the fix. It applies to kernel versions prior to the commit that introduced the correct guard on the retransmit path, and it is relevant to every Linux distribution that ships with an unpatched kernel, including Ubuntu, Debian, CentOS, RHEL, Fedora, and others.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%). The flaw is not listed in the CISA KEV catalog, implying that no widespread exploitation has been reported. Attackers would need to generate traffic containing urgent data and trigger a retransmission, which is a non‑interactive, network‑based attack vector that is theoretically possible but would require precise conditions and is unlikely to be widely abused. However, the data corruption it causes may produce cascading failures in mission‑critical services. As a result, the risk is moderate for environments that rely on urgent data handling, but low for typical IP traffic patterns where urgent data is rarely used.
OpenCVE Enrichment
Debian DLA
Debian DSA