Impact
The netfs subsystem failed to correctly cancel subrequests that could not be prepared, causing dangling references and queued entries to remain in kernel data structures. This flaw can lead to unreleased resources, corrupted internal state, and kernel crashes. The weakness is represented by CWE-125 and CWE-772, reflecting that internal pointers can become invalid during cleanup.
Affected Systems
All Linux kernel builds preceding commit 5366199be46fb5 are affected. Kernel distributions that have not incorporated this patch, regardless of distribution vendor or exact kernel release, remain vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity level, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability does not appear on the CISA KEV catalog. According to the description, exploitation would require triggering a failed read subrequest preparation; the CVE details do not confirm remote exploitation or privilege escalation capability. Successful exploitation could cause kernel instability or a denial‑of-service.
OpenCVE Enrichment
Ubuntu USN