Impact
In the Linux kernel’s orangefs filesystem driver, a readdir operation can trigger a deterministic double‑free of the trailer buffer when copy_from_iter_full() fails. The first free occurs in orangefs_devreq_write_iter(), but the pointer is not cleared before falling into error handling; later, do_readdir() frees the same buffer again. This double‑free corrupts the kernel heap, which may allow an attacker to execute arbitrary code or crash the system, depending on how the heap is subsequently used.
Affected Systems
All Linux kernel releases that include the orangefs module are affected. The vulnerability is triggered by a local user with access to the character device it does not require elevated privileges beyond those needed to perform the readdir operation.
Risk and Exploitability
The CVSS score of 4.1 and an EP probability of exploitation in the wild. The flaw is identified as CWE‑763 (Improper Memory Management). A malformed readdir downcall that causes copy_from_iter_full() to fail will trigger a deterministic double‑free leading to memory corruption that could result in denial of service or code execution if additional conditions are met. The vulnerability is not listed in the CISA KEV catalog, implying no known exploitation has been observed.
OpenCVE Enrichment
Debian DSA