Impact
A race condition exists in the Linux kernel’s ring‑buffer subsystem. The function ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, and if the cpu_buffer lock is not held during a resize operation, concurrent ring_buffer_alloc_read_page() or ring_buffer_free_read_page() calls can proceed. This missing lock introduces a classic race condition (CWE‑413) that can lead to corruption of the free_page state, potentially causing a denial of service or data integrity problems.
Affected Systems
The vulnerability affects the Linux kernel; no specific versions were disclosed, so all kernel releases prior to the patch that contain the unchecked ring‑buffer resizing logic are susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high risk. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting limited evidence of active exploitation. The attack vector is inferred‑access. Because the flaw arises from a missing lock, it is suitable for exploitation only in scenarios where an attacker can influence ring buffer usage.
OpenCVE Enrichment
Debian DSA