Impact
A NULL pointer dereference occurs in lookup_swap_cgroup_id when the kernel runs on a host without swap enabled. The function assumes a swap type has been registered, but on a swapless host the control structure’s map pointer is NULL, causing a crash during page fault handling or swap entry processing. The crash manifests as a BUG: unable to handle page fault and results in the system halting, providing a denial of service but no data compromise.
Affected Systems
The issue affects systems running the Linux kernel with the swapless configuration. Any distribution that ships the upstream kernel with the affected commit set (for example kernel 6.12.58) is vulnerable. There is no indication that particular distributions apply the fix earlier, so all Linux sellers should review whether their provided kernel includes the patch.
Risk and Exploitability
Based on the description, it is inferred that the attacker would need to corrupt a page table entry into a type‑0 swap entry, a condition that arises from a separate bug or a sophisticated fault‑injection scenario. The CVSS score of 5.5 indicates a moderate impact, meaning a successful exploitation would destabilize the system without necessarily compromising data. The EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Therefore the likely attack vector is local or requires an advanced fault‑injection technique, and the impact is limited to denial of service rather than data compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA