Impact
The vulnerability is an off‑by‑one error in XFS’s rtrefcount btree root level validation. It allows a crafted rtrefcount image to be accepted during mount or recovery, which then causes the kernel to write past a slab boundary. The result is a kernel panic and loss of operations, and could enable an attacker to gain elevated privileges or cause a denial of service.
Affected Systems
All Linux kernels that contain the unpatched rtrefcount btree code are affected, regardless of vendor distribution. No specific version numbers are listed, so any kernel build that predates the commit referenced in the advisory is vulnerable.
Risk and Exploitability
The bug results in an out‑of‑bounds memory write in the kernel, a high‑severitiy flaw that could be exploited by an attacker who controls the contents of an XFS filesystem or can trigger a mount during recovery. The CVSS score is not supplied in the advisory, the EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, but the nature of the flaw suggests a high likelihood of exploitation in environments where the attacker can influence filesystem contents.
OpenCVE Enrichment