Impact
An unprivileged process can create many special zero page and huge zero page table entries that the kernel incorrectly counts as file-backed pages. When the count of file‑backed mappings exceeds a limit, a BUG_ON triggers, causing the kernel to panic and the system to reboot. This flaw is a local denial‑of‑service vulnerability that can be exercised by any user without privileged access.
Affected Systems
All Linux kernel installations are potentially affected until the patch is applied, as the vulnerability is not tied to specific kernel versions in the public data. System administrators should treat every running kernel case as at risk until the update is in place.
Risk and Exploitability
The attack vector is local; no network exposure is required. The exploit involves allocating zero mappings to overflow the file_map_count counter. No known malware exploit exists in the KEV catalog and the EPSS score is not available, but the potential for a kernel panic means the risk is high for affected hosts. The CVSS score is not supplied, but the impact is significant for availability.
OpenCVE Enrichment