Impact
The smack module in the Linux kernel contains a use‑after‑free bug in smack_file_send_sigiotask(). The function wrongly accesses both tsk->cred and __task_cred(tsk) while a task’s credentials are being re‑assigned, leading to a freed credential structure being dereferenced. If an attacker can trigger the kernel to execute this code path on a local machine, the race can result in kernel memory corruption or the leakage of administrator credentials, effectively granting elevated privileges. The flaw is a classic use‑after‑free scenario (CWE‑825) that can be exploited from local user space.
Affected Systems
All Linux kernel releases that do not incorporate the commit that fixes smack_file_send_sigiotask() are vulnerable. The exact kernel version impacted cannot be enumerated without the advisory’s release notes, but any system running a kernel older than the first occurrence of the fix is at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high seriousness, while the EPSS score of < 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local process that forces the kernel to execute smack_file_send_sigiotask(), such as via interprocess signalling; this inference is drawn from the description of how the fix removed the race. Successful exploitation would require precise timing to create the race and is therefore technically challenging, but once achieved it can lead to arbitrary kernel execution and privilege escalation.
OpenCVE Enrichment
Debian DSA