Impact
The vulnerability lies in the NVMe subsystem of the Linux kernel, where the discard command always constructs a 4096‑byte payload irrespective of the number of ranges requested. Under normal conditions kzalloc zeroes the buffer, but if that allocation fails the code falls back to a per‑controller page obtained with alloc_page(GFP_KERNEL) that is never zeroed, thereby leaving 4080 bytes of stale kernel memory. Those bytes are then sent over the DMA channel to an NVMe controller, exposing arbitrary kernel data to anyone that observes or captures the controller’s traffic. This results in a kernel memory disclosure via an uninitialized DMA buffer, as identified by CWE‑824.
Affected Systems
Any Linux kernel that does not include the commit that zeroes the discard fallback page (commit 67551d84…) is affected. The fix was merged into the mainline kernel and is present in all subsequent releases; therefore, systems running a kernel older than that commit, or distributions that have not back‑ported the change, are vulnerable. The vulnerability applies to all NVMe controllers supported by the affected kernel versions.
Risk and Exploitability
Although the CVSS score is 7.5, the EPSS is below 1 % and the issue has not entered the CISA KEV list, signalling no known exploitation activity. Exploitation requires an extreme memory‑pressure event that causes kzalloc to fail, which is not feasibly triggered remotely. Consequently, while the risk is classified as high, the practical likelihood of an attacker successfully forcing the failure condition and leaking kernel data is low, but cannot be ruled out in environments with sustained memory pressure.
OpenCVE Enrichment
Debian DSA