Impact
The bug is located in the Linux kernel ring‑buffer implementation. When sub‑buffers are created with an allocation order greater than zero, the deallocation callback cpu_buffer::free_page is intended base order. This mismach between allocation and freeing sizes can corrupt kernel memory or CWE‑763.
Affected Systems
All Linux kernel builds that contain the affected ring‑buffer code are potentially impacted. The description does not specify a particular kernel release; any distribution that has not applied the patch that resolves the incorrect free_page order remains vulnerable.
Risk and Exploitability
With a CVSS base score of 4.4 and an EPSS value below 1 %, the likelihood that this flaw is leveraged in the wild is very low. The vulnerability is absent from the CISA KEV catalog. The flaw concerns a mismatch between allocation and freeing orders in the ring‑buffer module, so an attacker would have to invoke ring-buffer functionality with Based on the description, it is inferred that there is no publicly known or specified attack vector, and the current exploitation probability is minimal.
OpenCVE Enrichment
Debian DSA