Impact
The vulnerability in the Linux kernel’s LWT XMIT BPF path allows manipulation of sk_buff headroom during packet transmission. An attacker with the ability to load or register an LWT_XMIT BPF program can call bpf_skb_change_head to reduce the packet’s headroom, causing the post–transmission headroom check to accept an insufficient buffer. When the packet reaches neigh_hh_output, the kernel detects a headroom warning and drops the packet, resulting in loss of traffic or degraded network performance for the affected host.
Affected Systems
Linux kernel systems that have the lwt_bpf feature enabled and have not yet applied the patch to restore LL_RESERVED_SPACE usage in the post-BPF headroom check. The CVE does not specify particular kernel releases, so any kernel build before the fix is considered vulnerable.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score indicates a < 1% exploitation probability, and the vulnerability is not in the CISA KEV catalog. Exploitation requires local kernel-level access to load or modify an LWT_XMIT BPF program, so the attack vector is local. The overall risk is moderate: unpatched hosts could suffer packet loss or denial of service if an attacker gains the necessary privileges, but widespread exploitation is unlikely at present.
OpenCVE Enrichment
Debian DLA
Debian DSA