Impact
The_i the IOAS reference and its write lock when an xa_store() operation does not succeed. Because the current IOAS remains locked and an object reference is left unresolved, the bug results in a resource leak that can lead to device I/O failures or kernel instability over time. The flaw represents a CWE-772 missing release of a resource after acquisition.
Affected Systems
This issue resides in the generic iommufd driver that is part of the mainline Linux kernel. It potentially affects all Linux distributions that ship the default Linux kernel with this module enabled, unless a later kernel release back‑ports the fix. No specific version range is defined in the advisory, so all kernel versions before the patch are vulnerable. This inference is based on the vendor list and the description.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, implying no widespread exploitation has been reported. The likely attack vector is inferred from the kernel nature of the bug and would require a local attacker capable of executing privileged code or an attacker who can trigger a kernel failure that leaves the lock unreleased. Such an event would lead to a resource leak and possible deadlock, degrading system performance or causing kernel instability, but it does not enable remote code execution or direct data disclosure.
OpenCVE Enrichment