Impact
A flaw in the Linux kernel’s copy_net_ns error handling path causes a resource leak when the preinit_net function exits prematurely. Allocated network resources are not freed, allowing repeated triggering to drain kernel memory or network resources. This flaw can degrade system stability or cause crashes, representing a denial‐of‐service vulnerability.
Affected Systems
All Linux kernel versions that contain the original copy_net_ns implementation are affected. No specific version numbers are provided in the advisory, so any kernel build released before this patch is potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation. The attack vector is inferred to be local, requiring an attacker to initiate multiple network namespace creations or similar actions that exercise copy_net_ns. The fixed code removes the memory leak and prevents the resource exhaustion that could have been used for a denial‑of‑service attack.
OpenCVE Enrichment