Impact
The vulnerability arises when the virtual Ethernet driver fails to clear XDP program pointers during channel resize. Removing a receive queue tears down XDP resources but leaves the pointer dangling; if the program is then detached or replaced, the freed pointer remains. When the channel size is increased again, NAPI is re‑enabled and the kernel executes the freed program, causing a kernel panic. This use‑after‑free can also allow an attacker to execute arbitrary code with kernel privileges, effectively elevating local privileges or causing a denial of service.
Affected Systems
The flaw exists in the Linux kernel’s veth driver and therefore impacts all Linux kernel releases that contain this code path until the patch is applied. No specific version range is given, so it should be treated as a potential risk to all current kernel releases until the upstream fix is merged and distributed.
Risk and Exploitability
The CVSS score is not supplied, but the bug involves a use‑after‑free in the kernel, which typically carries a high severity rating. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to manipulate veth channel counts or otherwise trigger a channel resize while XDP programs are attached. The likely attack vector is local, involving privileged or compromised users who can control network interfaces.
OpenCVE Enrichment