Impact
The vulnerability is a race condition in the Linux kernel’s fsnotify subsystem that occurs when two fanotify or inotify marks on the same connector are modified concurrently. The kernel may skip recomputing the aggregate object mask if the cached aggregate already contains the newly added event bit, leading to a stale mask that omits the bit. As a result, applications receive a missed FAN_MODIFY or IN_MODIFY event when a file changes, which can cause incorrect application behavior or data loss. This is a non‑privilege‑escalation issue that only affects notification semantics.
Affected Systems
All Linux kernel distributions that include the pre‑fixed fsnotify code, specifically kernels up through the unmodified v6.12.95 release and any kernel that has not applied the upstream patch, are impacted. The affected CPE is Linux kernel and the flaw exists regardless of distribution or build options.
Risk and Exploitability
The CVSS base score is 2.5, indicating low severity, and the EPSS score is less than 1%, suggesting a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. An attacker would need to control two threads that modify fanotify or inotify marks on the same connector, which requires local or privileged execution on the system. The issue does not provide privilege escalation or remote code execution; it merely causes missed notifications. Given the low EPSS and the need for local execution, the overall risk is low to moderate, but missing notifications could impact services that rely on real‑time change tracking.
OpenCVE Enrichment
Debian DSA