Impact
The kernel bug causes a reference count underflow on an unsubmitted SCSI command in xen scsiback. When a pvSCSI guest sends a bad grant reference or an unknown request type, the underflow can leak all command tags of the LUN session or trigger a kernel panic under panic_on_warn. The result is a denial of service that can stop the virtual LUN or crash the host.
Affected Systems
All Linux kernel releases that include xen scsiback before the containment patch are affected. The issue applies to the generic Linux kernel and any distribution kernel that has not yet integrated the fix.
Risk and Exploitability
The vulnerability offers a path for guests running under Xen to emphasize kernel resource exhaustion. The CVSS score of 9.3 indicates a critical severity. The EPSS score indicates an exploitation probability of less than 1%, showing a very low but non‑zero likelihood of being exploited, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a guest capable of constructing malformed SCSI requests, which is inferred from the description of the issue.
OpenCVE Enrichment