Impact
In the Linux kernel, the inetpeer module historically used a deterministic Red‑Black tree keyed by IP address to store rate‑limiting entries. Because lookups followed a predictable lexicographical comparison, an off‑path attacker could model the tree’s topology and the exact sequence of nodes visited during a lookup. By combining this deterministic traversal with the kernel’s aggressive garbage‑collection threshold (triggered when the tree grows beyond inet_peer_threshold), an attacker could force chosen inet_peer nodes to be evicted. When the evicted node is recreated by a subsequent packet, its token bucket is reset to full capacity, effectively bypassing IP‑keyed ICMP or UDP rate limits and allowing the attacker to derive information such as whether a UDP port is open. This is a side‑channel flaw that can be exploited remotely to circumvent rate limits and conduct port probing.
Affected Systems
The vulnerability affects all Linux kernel versions that implement the unix inetpeer rate‑limiting subsystem without the SipHash‑based randomization patch. The specific vendor is Linux; the affected product is the Linux kernel. No version numbers are listed in the CNA data, so any kernel prior to the full implementation of the described mitigation is potentially affected.
Risk and Exploitability
The CVSS score of 9.4 classifies this flaw as critical, yet the EPSS score of less than 1 % indicates a very low current exploitation probability. The vulnerability is not in the CISA KEV catalog. Attacks would require an off‑path adversary that can send packets to the target host; by sending crafted traffic that targets specific IP addresses, the attacker can trigger the eviction gadget and reset rate‑limiting counters. The lack of a known active exploit at this time suggests that the primary risk lies with the vulnerability’s potential for remote abuse and the side‑channel information disclosure it enables.
OpenCVE Enrichment
Debian DLA
Debian DSA