Impact
The Linux kernel networking scheduler "teql" module fails to restore the skb->dev pointer after a slave transmission error, leaving the packet structure pointing to a freed network device. When the packet later reaches neighbor resolution code, a use‑after‑free occurs, causing a kernel panic or potentially enabling arbitrary code execution. This bug is a classic use‑after‑free flaw that can destabilise the system.
Affected Systems
Linux kernels that implement the TEQL network scheduling scheme are affected, including all releases prior to the patch that restores skb->dev on the slave failure path. The Linux vendor "Linux:Linux" is responsible for the affected product. No specific version information is provided in the available data.
Risk and Exploitability
The EPSS score for this vulnerability is less than 1 %, indicating a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves a local or privileged user sending crafted network packets that trigger the slot failure path, leading to the use‑after‑free. The CVSS score of 7.8 reflects a high severity of this issue.
OpenCVE Enrichment
Debian DLA
Debian DSA