Impact
During a kernel read operation on a netfs‑mounted filesystem, the function netfs_read_to_pagecache would normally stop generating new subrequests if a previously sent subrequest failed. The missing check caused the kernel to continue generating subrequests, potentially leading to uncontrolled allocation of kernel buffers and consuming system resources. An attacker who can trigger multiple failed subrequests generation could degrade performance or cause the system to become unresponsive. This flaw is identified as a critical kernel bug with a CVSS score of 9.8. The CVE description does not explicitly state the attacker’s capability; thus the possibility of an attacker triggering the failure is inferred.
Affected Systems
All releases of the Linux kernel that contain an unpatched netfs subsystem are vulnerable. The vendor enumeration lists generic Linux:Linux; no specific kernel version numbers are provided. System administrators should compare the kernel version of their host against the latest official kernel releases to determine whether the fix is present.
Risk and Exploitability
The high severity CVSS score indicates that exploitation could produce a denial‑of‑service condition affecting system availability. The EPSS score of less than 1 % suggests a low likelihood of immediate exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The flaw resides at kernel level; therefore the attack vector is likely local or at most privileged. This assessment of local or privileged attack vector is inferred based on the kernel‑level nature of the flaw. No public exploit has been disclosed, but the nature of the flaw warrants immediate attention.
OpenCVE Enrichment
Ubuntu USN