Impact
In the Linux kernel bridge networking code, a logic flaw permits VLAN and tunnel IDs that descend to bypass the range span check. The resulting subtraction can produce a negative integer that is cast to unsigned, causing the check to incorrectly succeed. The subsequent loop performs no iterations, leaving an error variable uninitialized. The batched notification handling then uses this uninitialized value when returning, producing unpredictable return values and potentially destabilizing kernel operations.
Affected Systems
This issue is present in any Linux kernel implementing the bridge networking stack that has not applied the patch. No specific kernel versions are listed, so all affected distributions using an unpatched kernel are potentially impacted.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not included in CISA KEV, indicating limited exploitation activity to date. The exploit requires kernel-level code execution, likely via local or escalated privileges, and targets the bridge configuration interface. While direct data leakage is not indicated, the unpredictable return values could be leveraged to cause a denial of service or further kernel instability.
OpenCVE Enrichment
Debian DLA
Debian DSA