Impact
A race condition exists between page_pool_scrub() and page_pool_put_netmem(), which can cause the kernel to free a page that is still being processed; this use‑after‑free results in corruption of kernel memory and can be leveraged by an attacker with local or privileged access to achieve arbitrary code execution or cause a kernel crash.
Affected Systems
All Linux kernel installations that have not applied the commit identified by 24ef02f9 (or an equivalent upstream patch) are affected. The vulnerability was discovered during operation of the hns3 driver on arm64, but the flaw is present in the generic page_pool implementation and therefore applies to any kernel version lacking the fix, regardless of distribution or specific version number.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. Exploitation would require an attacker to be able to trigger channel reconfiguration while network traffic is active, which generally implies local or privileged access. If successfully exploited, kernel memory corruption could lead to privilege escalation or a denial‑of‑service via kernel crash.
OpenCVE Enrichment
Debian DLA
Debian DSA