Impact
A use‑after‑free flaw exists in the SUNRPC cache cleanup routine of the Linux kernel; the bug causes a freed cache_detail structure to be accessed by a background cleaner work item, leading to corruption of kernel data structures and the potential for arbitrary code execution at kernel privilege level, as indicated by its classification as CWE‑825.
Affected Systems
The vulnerability affects the SUNRPC subsystem in the Linux kernel, which manages RPC transmission caches across network namespaces. Any Linux kernel branch that loads this subsystem and handles RPC traffic could be exposed; however, the data does not provide specific affected versions, so version information is missing. System administrators should verify that the SUNRPC module or rpcbind service is installed and functioning, as these components provide the attack surface.
Risk and Exploitability
The CVSS score of 7.8 signals a high‑severity flaw, and the EPSS score of < 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves exploiting the use‑after‑free during SUNRPC cache cleanup, which could be triggered by an attacker sending crafted SUNRPC traffic or manipulating RPC connection teardown, potentially leading to kernel privilege execution if successful.
OpenCVE Enrichment
Debian DSA