Impact
The Xen netfront driver in the Linux kernel does not verify that the first received packet contains at least the length of an Ethernet header. When a packet shorter than ETH_HLEN is received, the driver pulls an incomplete header into the skb, causing eth_type_trans() to trigger a BUG in __skb_pull(). This results in a kernel oops and can bring the host down, providing a denial‑of‑service path for attackers who send crafted packets.
Affected Systems
All Linux kernels that incorporate the Xen netfront module are affected, regardless of distribution or specific release version. The issue exists in the generic kernel code for Xen front‑end drivers, so any system running a Xen host with the netfront driver enabled is potentially vulnerable.
Risk and Exploitability
The flaw can be exploited by sending malformed network traffic to the Xen host. No exploitation probability is reported (EPSS not available) and the vulnerability is not listed in the CISA KEV catalog. However, the lack of input validation allows an unauthenticated remote attacker to force a kernel crash, resulting in service interruption or reboot of the host.
OpenCVE Enrichment