Impact
The defect occurs when the liveupdate subsystem fails to increment the reference count for incoming File‑Lifecycle‑Bound data. As a result, the structure can be freed while in use, creating a use‑after‑free condition that corrupts kernel memory. This flaw could allow privileged code to execute arbitrary instructions within the kernel, potentially leading to full system compromise.
Affected Systems
All versions of the Linux kernel that contain the liveupdate module but do not yet contain the reference‑count fix are affected. The fix is referenced by commit hashes 725ada0273a0f48a67fd59cc518d7f8055fe3d5c and d8e47bd066d7e626f9f45d416182d585b7e18b9b. No specific distribution versions are enumerated, so any distribution shipping an unfixed kernel (including custom builds) is at risk.
Risk and Exploitability
The vulnerability is an unprotected use‑after‑free in privileged kernel code. Attackers would need local or compromised kernel privileges to trigger a live update that uses the FLB data. While the exact CVSS and EPSS scores are unavailable, the nature of the flaw suggests a high impact; it can lead to system‑wide memory corruption and arbitrary code execution. The lack of a KEV listing does not reduce the urgency; the fix should be applied promptly.
OpenCVE Enrichment