Impact
The Linux kernel can leave certain struct pages uninitialized when DAX memory is hot‑plugged into an early subsection that has not been optimized by the boot memmap. The uninitialized tail pages can later be used in a way that causes the kernel to behave unpredictably or crash, resulting in a loss of availability for the affected system. This flaw is a classic case of a use‑of‑uninitialized‑memory weakness that can be triggered by the specific memory‑management scenario described.
Affected Systems
The fault affects the Linux kernel; the specific kernel versions are not listed in the advisory, so any kernel in which the early ZONE_DEVICE sections can be hot‑plugged DAX memory without the fix remains vulnerable. No product sub‑version information is provided, so the impact applies broadly to all kernel builds that include the unsupported hot‑plugging path.
Risk and Exploitability
No CVSS score is supplied and the EPSS score is unavailable, so a numerical severity assessment cannot be made. The vulnerability is not listed in CISA’s KEV catalog and there are no publicly reported exploits. However, a local privileged user or a compromised kernel process could trigger the hot‑plugging path and cause a crash, making the risk high for environments that enable DAX memory hot‑plugging. The lack of exploitation evidence reduces immediate threat, but the crash potential warrants timely remediation.
OpenCVE Enrichment