Impact
The Linux kernel bug in the net/smc subsystem causes a stashed qentry to be overwritten without freeing the previous allocation, resulting in a single kmalloc memory leak. This leak can, over time, exhaust system memory reserves and degrade stability, but it does not provide direct code execution or privilege escalation.
Affected Systems
All active Linux kernel installations are affected because the flaw resides in the core kernel networking code. The issue is present in any distribution that ships an unpatched kernel containing the buggy net/smc implementation.
Risk and Exploitability
The EPSS score is below 1 % and the flaw is not listed in CISA’s KEV catalog, indicating that the likelihood of exploitation is low. No remote attack vector is documented; an attacker would need local access to trigger the specific SMC flow transition that leads to the leak. The primary impact is a denial‑of‑service risk rather than privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA