Impact
The Linux kernel’s zero‑copy path for AF_XDP sockets incorrectly treats transmit metadata when the user memory has metadata space, even if a descriptor does not set the XDP_TX_METADATA flag. As a result, the kernel reads and uses metadata that is not explicitly requested, potentially leading to improper offload configuration or overwriting of data such as timestamps when XDP_TXMD_FLAGS_TIMESTAMP is unset. This flaw is an example of CWE‑20 – improper validation of user input, which can allow attackers to influence kernel memory operations and compromise system integrity.
Affected Systems
All Linux kernel releases that employ the AF_XDP zero‑copy path with UMEM metadata support are affected. No specific version range is provided, so any kernel that includes the vulnerable zero‑copy logic without the applied patch is considered at risk. Users running network stacks that rely on XDP sockets need to verify their kernel version.
Risk and Exploitability
The EPSS score being less than 1% suggests a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the deficiency remains susceptible to malicious manipulation of network traffic and could lead to memory corruption or denial of service if an attacker can craft descriptors that trigger the erroneous metadata handling. The CVSS score is not supplied, but the impact could be high if the flaw is leveraged in an environment with privileged network activity. Patch deployment is recommended even though the immediate risk appears modest.
OpenCVE Enrichment