Impact
The vulnerability resides in the traffic‑control action act_ife within the Linux kernel. It incorrectly assumes every socket buffer carries an Ethernet header by using skb->dev->hard_header_len, which is only valid for Ethernet devices. When packets come from non‑Ethernet interfaces such as PPP, the header length used is wrong, leading skb_push and skb_pull to touch the buffer with an invalid offset. This can invoke skb_under_panic and crash the kernel, causing a denial‑of‑service and potentially corrupting kernel memory. The impact is a kernel panic and the loss of service for the affected host.
Affected Systems
The flaw is present in all Linux kernel builds that include the act_ife action before the patch was merged. The vendors list indicates the Linux kernel, and the affected product is the kernel as a whole. No explicit version range is published, so any kernel prior to the commit that logs the specific changes in the referenced URLs is vulnerable. Updating to the latest kernel that incorporates this commit removes the issue.
Risk and Exploitability
The EPSS score is below 1% and the flaw is not present in the CISA KEV catalog, indicating a low probability of exploitation. Nevertheless, the severity is high—the bug can be triggered by sending traffic that is redirected from a non‑Ethernet interface to a device employing act_ife. An attacker with the ability to inject packets or control mirred redirection is sufficient to cause a kernel panic. Because the potential impact is catastrophic and the exploit requires only a crafted packet, the prudent response is to apply the patch immediately, as the risk of damage outweighs the very low likelihood of exploitation.
OpenCVE Enrichment