Impact
An improper handling of the virtual‑network packet ring causes a race condition that can leave a ring slot claimed after a failed header conversion. When a single‑frame TPACKET_V2 ring receives an unsupported UDP GSO packet, the only slot remains unavailable and the next valid packet is dropped, resulting in loss of traffic. The flaw does not disclose data or provide privilege escalation, but it can disrupt normal network operation by dropping legitimate packets and potentially blocking service if the loss is severe.
Affected Systems
The affected component is the Linux kernel’s networking packet receive path (tpacket_rcv). The issue exists in kernels that support a V1 or V2 ring slot map before conversion of virtio‑net headers. The patch fixing the bug (commit 61fad6816fc1) has been incorporated in later kernel releases; any earlier kernel version that includes this commit chain remains vulnerable.
Risk and Exploitability
Exploitability is not quantified by EPSS and the vulnerability is not listed in CISA’s KEV catalog, indicating a lack of widely available public exploits. An attacker could trigger the race condition by sending specially crafted UDP GSO packets into a host using a single‑frame TPACKET_V2 ring, leading to packet loss and a potential denial of service to applications relying on those packets. The likelihood of random failure is low, but an adversary who can inject traffic to the target can reliably exploit the flaw.
OpenCVE Enrichment