Impact
The vulnerability occurs in the Linux kernel when the remote swap_reader_page callback can return an error such as -EBUSY, but the kernel code still continues to use the stale reader ID and rearranges the ring buffer page list as though the swap succeeded. This incorrect handling can leave the same memory page marked as both the previous and new reader, potentially corrupting kernel memory. The flaw is a failure to properly handle an error return, identified by CWE-390.
Affected Systems
All Linux kernel releases that do not include the commit referenced in the advisory are affected. The vendor list indicates the entire Linux kernel product line, and no specific version ranges are provided, so any distribution shipping an unpatched kernel is at risk.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity vulnerability that can lead to data integrity loss. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the issue is not listed in CISA's KEV catalog. Although no public exploits are known, the likely attack vector involves a local or privileged process that can trigger event storms on small ring buffers, thereby exercising the faulty path.
OpenCVE Enrichment