Impact
The flaw exists in the hinic3 NIC driver where it caches an SKB fragment count before calling a checksum offload routine. If a checksum helper linearizes the SKB, the driver continues to use the stale fragment count, causing its generated TX descriptor to misrepresent the packet structure. This mismatch can trigger out‑of‑bounds DMA reads or IOMMU faults, exposing kernel memory to corruption. In addition, the driver previously ignored the return value of the checksum helper, which meant corrupted packets could be transmitted. The net effect is potential kernel memory corruption that, if exploited, could allow a local attacker to elevate privileges or execute code in kernel mode (inferred).
Affected Systems
All Linux kernel releases that incorporate the hinic3 NIC driver before the current patch are vulnerable. The vulnerability applies to any system running a Linux kernel with the buggy hinic3 implementation, regardless of distribution specifics. No precise version range is disclosed, so any kernel containing the original code path is considered at risk.
Risk and Exploitability
The CVSS score of 7.1 signals high severity, and the EPSS score of < 1% indicates a low but non‑zero likelihood of exploitation in the wild. This issue is not included in CISA’s KEV catalog. Exploitation would require an attacker to send or manipulate packets that reach the affected NIC, implying local or compromised‑host attackers are the primary threat actors. While remote exploitation probability is uncertain, the potential for kernel memory corruption warrants serious consideration and swift mitigation.
OpenCVE Enrichment