Impact
A flaw in the Linux kernel's netdevsim implementation caused a use‑after‑free in the NAPI subsystem. When a queue reset operation swapped in a new queue structure without updating the kernel’s internal queue‑to‑NAPI mapping, the old NAPI pointer remained in the device’s receive queue array. After the old structure was freed, a subsequent queue inspection via Netlink attempted to read the NAPI identifier, triggering the Kernel Address Sanitizer and exposing the stale pointer. The result is a kernel crash rather than arbitrary code execution, but the crash can be forced by an attacker who can reset queues or request queue dumps, leading to a denial‑of‑service of the affected system.
Affected Systems
The vulnerability exists in all kernel builds that contain the netdevsim driver. It affects Linux kernel releases prior to the introduction of the fix, which can be identified by the absence of the netif_queue_set_napi() call in nsim_queue_start(). No specific version numbers were supplied, so all legacy kernel installations lacking this patch are vulnerable.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score remains below 1 %, indicating a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Because the vulnerability requires the attacker to perform a queue reset and then request a queue dump, it is an in‑kernel use‑after‑free that results in a crash. While the attack vector is local and requires sufficient privileges to manipulate queue state, the compounded impact remains denial of service rather than privilege escalation or data exfiltration.
OpenCVE Enrichment