Impact
A flaw in the Linux kernel’s traffic-control skbmod action miscalculates buffer lengths when processing packets on TC ingress. The incorrect calculations trigger warnings, cause skb_ensure_writable to request more space than the packet holds, and result in legitimate short packets (for example, 28‑byte UDP/IPv4 packets) being dropped. The vulnerability therefore enables an attacker to induce packet loss and disrupt network communication, but it does not provide a path to arbitrary code execution or privilege escalation.
Affected Systems
The defect resides in the Linux kernel’s traffic‑control subsystem, affecting any Linux system whose kernel implements the act_skbmod filter for TC ingress operations. Specific kernel releases are not enumerated, so all affected kernels prior to the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is less than 1 %, indicating a very low probability of actual exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require an attacker to be able to influence packets processed by the TC ingress hook—either by sending crafted packets to a device such as a TUN interface or by running code on the host that applies the vulnerable tcf_skbmod action. While the impact is limited to denial of service through packet drops, low EPSS and lack of broader exploitation vectors keep the overall risk moderate on a system‑wide scale.
OpenCVE Enrichment
Debian DLA
Debian DSA