Impact
A defect in the Linux kernel cachefiles module causes vfs_mkdir() error pointers to be ignored when the call fails, which results in a zero error code and an ERR_PTR(0) value that is interpreted as NULL. This misreporting makes callers believe that a directory creation succeeded when it actually did not, potentially leading to logic errors, incorrect assumptions about the file system state, and subsequent operations on a non‑existent path. The weakness is an improper return value handling (CWE-252) with a null reference exception scenario (CWE-476).
Affected Systems
Any Linux kernel build that includes the cachefiles module and predates the patch commit 0940108d27c6 is affected. This includes the 7.1 series release candidates and any custom or embedded kernels that incorporate the module without applying the provided fix.
Risk and Exploitability
The CVSS score of 5.5 places this flaw in the medium severity band, reflecting its limited scope to error reporting rather than direct system compromise. The EPSS score is <1%, indicating a very low likelihood of actual exploitation, and the vulnerability is not listed in the CISA KEV catalog. While it does not grant direct code execution, the false success state can lead to cascading system instability or subtle logical errors, making the overall risk moderate and worth addressing promptly.
OpenCVE Enrichment
Ubuntu USN