Impact
The vulnerability arises when a cached reader page is discarded during a ring buffer resize that happens concurrently. The free_pages() call uses a new global subbuf_order value, which may differ from the order that allocated the page. As a result, the page is freed with an incorrect order, causing kernel memory corruption that can lead to a crash or a memory leak. This race condition is classified as CWE‑763.
Affected Systems
All instances of the Linux kernel containing the ring-buffer implementation that have not been updated with the recent patch are impacted. Information on specific kernel versions is not provided, so any kernel using the unpatched ring-buffer code carries the risk.
Risk and Exploitability
The CVSS score is 7.8, and the EPSS score is less than 1%, indicating a low probability of exploitation. The flaw is not listed in CISA KEV. Based on the description, it is inferred that exploitation would likely require a concurrent ring-buffer resize, which in practice would need privileged access or a high level of interaction with kernel memory. Because of these restrictions and the low EPSS, the overall risk is moderate, though a successful exploit could destabilize or crash the system.
OpenCVE Enrichment