This crash is due to the dn_nsp_send function (net/decnet/dn_nsp_out.c) which, first off, causes a Denial of Service by preventing the release of locks such as the current sock's sk->sk_lock, but could also lead to Local Privilege Escalation under certain conditions. https://seclists.org/oss-sec/2023/q2/276
*** This bug has been marked as a duplicate of bug 2218618 ***