Impact
A flaw in the Linux kernel’s virtio_net driver causes the RX ring buffer array to be resized incorrectly when an AF_XDP socket is attached. The driver writes past the end of the XSK buffer array, creating an out‑of‑bounds write. This buffer overflow can corrupt kernel memory, leading to a crash or, if an attacker controls the data that triggers the resize, the possibility of executing arbitrary code on the host.
Affected Systems
All Linux kernel installations that include the virtio_net driver and employ AF_XDP sockets are affected. The issue applies to any kernel version built with the vulnerable virtio_net implementation, regardless of distribution, until the patch that fixes the resize logic is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw, but the EPSS score is below 1%, showing a very low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker manipulating XSK buffer sizes or initiating an AF_XDP socket on a system exposed to untrusted traffic, which could trigger the vulnerable resize path. Based on the description, it is inferred that an attacker could cause kernel memory corruption, potentially leading to a crash or remote code execution.
OpenCVE Enrichment