Impact
The Linux kernel bug prevents the regeneration of temporary IPv6 privacy addresses after a router temporarily deprecates an IPv6 prefix and later restores it. As a result, the kernel permanently loses the ability to generate temporary addresses for that prefix, so the interface keeps using legacy addresses. This reduces privacy protection and can make the device easier to track.
Affected Systems
This issue affects the Linux kernel on all distributions that use the affected kernel code. The specific vendor entries are Linux: Linux, and the vulnerability applies to any kernel version that has not incorporated the posted patch. No explicit version range is provided in the CNA data.
Risk and Exploitability
The vulnerability does not provide a direct attack vector such as remote code execution. It does not appear in the CISA KEV catalog, and no EPSS score is available. The primary concern is loss of privacy through potential tracking of the device’s IPv6 address over time. Because the flaw hinges on a routing advertisement and kernel state, exploitation would require direct control over network advertisements or an attacker residing on the same local network, which limits likelihood. Nevertheless, the persistent use of stale addresses can increase the risk of device discovery and correlation over multiple sessions.
OpenCVE Enrichment