Impact
A slab use‑after‑free occurs in slip_receive_buf() when a tty hangs up concurrently; slip_hangup() calls slip_close() which unregisters and frees the net device. A reader in slip_receive_buf() can then dereference freed memory, potentially allowing an attacker to read arbitrary kernel memory or trigger a crash. The weakness is a use‑after‑free flaw that can impact confidentiality and system stability.
Affected Systems
The vulnerability affects the Linux kernel’s slip line‑discipline driver. No specific kernel versions are listed; any build that enables the slip protocol is potentially affected until the issue is patched.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 %, suggesting low likelihood of exploitation as of the current data, and the flaw is not yet listed in CISA’s KEV catalog. Attackers would need to trigger the race condition by causing a tty hangup while the slip protocol is in use; this likely requires local privileges or the ability to control a tty device. Once triggered, the use‑after‑free could expose kernel memory or destabilize the system, but no community‑reported exploits are known at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA