Impact
The bug in the STMMAC Ethernet driver removes the required NET_IP_ALIGN padding from the receive buffer offset. As a result, on architectures where the IP header must be aligned, the header lands at an unaligned memory address. This unaligned access triggers an alignment exception in the kernel, causing it to panic. The effect is a denial‑of‑service that crashes the entire host whenever a packet in the RX path misaligns the IP header.
Affected Systems
All Linux kernel builds that include the STMMAC driver in zero‑copy mode are potentially affected. The flaw exists in any kernel version prior to the commit that restores NET_IP_ALIGN to the RX offset. Affected vendors are the upstream Linux kernel maintainers; specific release versions are not listed in the advisory.
Risk and Exploitability
The EPSS score is listed as less than 1%, indicating a very low probability that the vulnerability is actively exploited in the wild. The CVSS score is 7.5, indicating a medium‑to‑high severity risk. The vulnerability is not currently in the CISA KEV catalog. Attackers would need network connectivity to the affected host and could trigger the kernel panic by sending normal packets, such as an ICMP echo request. Because the flaw causes a crash rather than privilege escalation or data disclosure, the risk is primarily a disruption of service. The lack of a high exploitation rate suggests that a cautious approach—verify whether the system is running a vulnerable kernel and apply the fix—suffices for mitigation.
OpenCVE Enrichment