Impact
The function esp_ssg_unref() in the Linux kernel incorrectly releases page references on managed fragment SKBs. Because it drops a reference that was never held, the page reference count can underflow, resulting in a kernel page being freed while still in use. This leads to memory corruption and could be escalated to arbitrary code execution if an attacker can supply crafted packets that trigger the faulty paths.
Affected Systems
All Linux kernel releases that include the esp scatterlist handling code are affected, because the vulnerability is in a core networking subsystem. The issue exists until the kernel is patched with the commit that adds the missing guard for SKBFL_MANAGED_FRAG_REFS. No specific vendor or product version is listed, so any distribution using an unpatched kernel is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely. The failure occurs during packet processing, but it is not explicitly stated whether it can be triggered by external traffic. Based on the description, it is inferred that sending crafted network traffic that contains zero‑copy managed fragments could trigger the faulty code path. If an attacker can do so, the low likelihood is outweighed by the high impact of possible kernel memory corruption or code execution.
OpenCVE Enrichment