Impact
The Linux kernel allows a double free of a network buffer, or skb, within the xfrm_dev_direct_output function. When the local_out function returns a code other than 1, the skb is considered consumed or ownership has been transferred. However, xfrm_dev_direct_output still frees the skb, resulting in a double free. This bug can corrupt kernel memory, and it is inferred that this could lead to arbitrary code execution or a kernel crash, as the freed memory may be reused for malicious data or used by other kernel structures.
Affected Systems
Linux kernels of all versions prior to the patch that addresses this bug are affected. The vendor is Linux, and the product is the Linux kernel. The exact version range is not specified in the CVE data, so all builds before the incorporated patch commit (e.g., 02deb637e965950148752a304dd1471212dd6470) remain vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, while the risk is severe, the likelihood of exploitation at this time is low. The vulnerability is not marked in the CISA KEV catalog. Based on the description, it is inferred that exploitation would most likely occur via crafted network traffic that forces local_out to return a non-1 status, thereby triggering the double free path in xfrm_dev_direct_output. Because the flaw is kernel-level, successful exploitation could lead to privilege escalation or complete system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA