Impact
A flaw in the Linux kernel AMT driver permits a lower network device to be unregistered while a corresponding upper AMT device in a different network namespace remains linked. The kernel incorrectly looks up the upper device only within the lower device's namespace and then unregisters just a single upper device. When the lower device is removed, this mismatch causes the kernel to hang and eventually crash, producing a denial‑of‑service condition. The weakness is a classic use‑after‑free or dangling‑pointer scenario that can be triggered by any process that creates AMT devices across network namespaces and then deletes the lower device. The impact is a kernel crash and loss of availability for the host.
Affected Systems
All Linux kernel implementations are affected, as indicated by the vendor/product listing "Linux:Linux" and the generic CPE string for the linux kernel. Any system running the kernel without the recent patch that forbids cross‑namespace AMT setups is vulnerable.
Risk and Exploitability
The CVSS score is not supplied, but the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits at the time of analysis. The likely attack vector is a local or highly privileged process that can create or remove AMT network devices, such as system administrators or compromised kernel modules. Because the flaw leads to a kernel panic rather than data exfiltration, the primary risk is service disruption rather than confidentiality or integrity compromise.
OpenCVE Enrichment