Impact
In the Linux kernel XFS filesystem, a missing release of the dquot lock during quota scrub operations can leave the lock held when an error occurs early in the scrub. This lock leak can lead to deadlocks or resource exhaustion in later quota management activities, impacting system availability rather than confidentiality or integrity.
Affected Systems
All Linux kernels that enable XFS quota support are vulnerable, including kernel 6.8 and all 7.0 release candidates (rc1 through rc7). Kernels that are compiled without XFS or without quota support are not affected. The vulnerability affects the core quota subsystem and is present until the kernel patch that unlocks the lock before early return.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity incident, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, further indicating low prevalence. Based on the description, it is inferred that an attacker would need to trigger a quota error while operating on an XFS filesystem, which at minimum requires local access or root privileges. While feasible in a controlled or privileged environment, the limited attack surface and low exploitation likelihood reduce the overall risk compared to higher‑impact flaws.
OpenCVE Enrichment
Debian DSA