Impact
The Linux kernel contains a NULL pointer dereference in the __xsk_rcv() function when processing XDP socket buffers. When an attacker sends specially crafted traffic or triggers the XDP path repeatedly while the buffer allocator fails, the kernel dereferences a NULL pointer, causing a general protection fault and an Oops. This results in a kernel crash that brings the affected system down, leading to a denial of service. The bug is a classic NULL pointer dereference weakness (CWE‑476).
Affected Systems
All Linux kernel installations that do not yet contain the commit that patches __xsk_rcv() are at risk. The fix has been committed to the mainline kernel; the advisory does not list specific affected versions, so any kernel prior to the inclusion of the patch should be considered vulnerable.
Risk and Exploitability
The attack vector occurs over the network via XDP sockets; a malicious user could send packets that exercise the failing allocation loop to trigger the crash. Although the EPSS score is below 1%, indicating a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog, a successful exploit would cause an immediate service disruption. The vulnerability does not permit remote code execution; the primary risk is to system availability.
OpenCVE Enrichment
Debian DLA
Debian DSA