Impact
This vulnerability is a race condition in the Linux kernel's xfrm state management that can lead to a use‑after‑free of an xfrm_state object. During a device state flush, the code releases a lock before calling a driver callback that may sleep, allowing the garbage collector to free the same state concurrently. The resulting double free can corrupt kernel memory and potentially crash the system or allow an attacker to execute arbitrary code if they can trigger the race.
Affected Systems
The flaw affects the Linux kernel across all versions that implement the xfrm state device cleanup routine, as described in the kernel source. No specific versioning is provided, so any kernel build containing the xfrm code before the patch is potentially vulnerable. The vendor identifier is Linux:Linux, referencing the open‑source Linux kernel.
Risk and Exploitability
The Common Vulnerability Scoring System (CVSS) value is not available, and the exploit probability score (EPSS) is not provided; the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Nevertheless, a use‑after‑free in kernel code is a high‑risk flaw that can lead to denial of service or remote code execution if an attacker can trigger the race. The attack vector likely requires local privileges or the ability to manipulate kernel networking state, but absence of public exploits makes the realistic risk uncertain.
OpenCVE Enrichment