Impact
The Linux kernel creates an internal TCP socket when an IPPROTO_SMC socket is opened. If the socket creation fails after the TCP socket has been allocated, that internal socket is not released because neither smc_inet_prot nor smc_inet6_prot defines a .destroy hook. The result is a memory leak of the TCP socket struct. By attaching an unprivileged BPF_CGROUP_INET_SOCK_CREATE program that denies socket creation to its own cgroup, an attacker can repeatedly attempt to create the failing socket and cause the kernel memory usage to grow arbitrarily, eventually leading to a denial‑of‑service event when the kernel runs out of memory.
Affected Systems
All Linux kernel releases before the commit that introduces the .destroy hook for smc_inet_prot and smc_inet6_prot are affected. This includes the kernels used by major distributions such as Ubuntu, Debian, CentOS, Fedora, Red Hat Enterprise Linux, and others that ship the kernel without the patch.
Risk and Exploitability
The EPSS score is <1%, indicating a very low probability that this vulnerability will be exploited in the wild. The vulnerability is not present in CISA’s KEV catalog and there are no publicly known exploit code or reports. The attack vector requires a local unprivileged user with the ability to attach a BPF program that denies socket creation to its cgroup. While feasible, the exploitation path is somewhat involved and the impact is limited to kernel memory exhaustion, making the practical risk moderate until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA