Impact
The Linux kernel’s huge page unmapping routine incorrectly decrements a reservation counter without first verifying that the mapping is the last reference. When a page is mapped in a parent and child and the parent unmaps first, the counter underflows. This bug results in corrupted reservation bookkeeping, affecting the kernel’s memory accounting. The flaw is an integer underflow (CWE‑191).
Affected Systems
All Linux kernel releases prior to the patch commit are affected. The vulnerability exists in the generic Linux kernel and applies regardless of distribution or build variant.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high severity. Exploitation requires a process that can map and unmap huge pages, a capability normally restricted to privileged users or to processes running with CAP_SYS_ADMIN. The EPSS score of less than 1% implies a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. the underflow.
OpenCVE Enrichment
Debian DSA