Impact
A missing cleanup routine in the Linux kernel’s network device allocation path leaves a reference tracker directory unfreed when the allocation of per‑CPU data or the initialization of a device address fails. Accessing the /sys/kernel/debug/ref_tracker/* interface at that point triggers a use‑after‑free crash, causing a kernel panic. The vulnerability does not provide direct code execution or data exfiltration, but it can be leveraged to disrupt system availability by bringing the kernel down.
Affected Systems
All Linux kernel releases prior to the fix for commit 4d92b95ff2f9 are affected. The issue was introduced by the refcount tracker infrastructure added in that commit and applies to any build that includes the network device allocation function alloc_netdev_mqs(). Vendor‑specific version information is not supplied in the CVE data, so administrators should assume all affected kernel versions require remediation.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the vulnerable kernel (or remote if the debug filesystem is exposed), and the impact is limited to a denial of service rather than privilege escalation. Given the limited attack surface and low exploitation likelihood, the overall risk is moderate, but the potential for a system crash means it should be treated as a high severity issue within an incident response context.
OpenCVE Enrichment
Debian DLA
Debian DSA