Impact
The flaw arises when the IPVS FTP helper parses a FTP PASV or EPSV response that contains exceedingly long numeric fields. The helper accumulates digits into a 16‑bit variable and into an unsigned byte array without bounds checks, allowing an overflow that truncates the port or address values. This could result in the helper establishing a data connection using incorrect parameters, potentially allowing an attacker to influence the data link or bypass expected filtering. The vulnerability is an integer overflow, and it directly impacts the integrity of data connections established by IPVS.
Affected Systems
Affected systems are Linux kernel users that employ the IPVS FTP helper. The vulnerability is present in any kernel build that does not include the commit that widens the accumulator to a 32‑bit integer and rejects values above the legal limits. The specific versions affected are not listed in the advisory, so any kernel prior to the application of the fix is considered vulnerable.
Risk and Exploitability
The risk is rated as a high‑severity CVSS score of 7.3 with an exploit probability of less than one percent according to EPSS. The vulnerability is not listed in CISA’s KEV catalog. The attack requires an attacker to send a specially crafted FTP PASV or EPSV reply to a host that is running the IPVS FTP helper, so the vector is network‑based and contingent on the helper being active.
OpenCVE Enrichment
Debian DLA
Debian DSA