Impact
Statfs() can be invoked by any unprivileged user on the efivarfs mount point, causing the kernel to call the firmware runtime service QueryVariableInfo() repeatedly. On x86 machines where the EFIVAR store is backed by System Management Mode, each such call forces a rendezvous of all CPUs, which is computationally heavy. The repeated invocations can therefore drain CPU resources, leading to degraded performance or service denial for other workloads.
Affected Systems
No specific kernel versions are listed in the CNA data; the vulnerability’s status is tied to the presence of efivarfs before the patch commit. Any Linux kernel that mounts efivarfs and is not built from a version containing the commit 0dbc2e94b81df5a1264068b6ed3605c654b8afcb is potentially vulnerable. The exact affected version range is not disclosed.
Risk and Exploitability
The CVSS score of 4.7 indicates low-to-medium severity. EPSS < 1% suggests exploitation is unlikely, and the vulnerability is not in CISA KEV. The attack vector is local with unprivileged access to the efivarfs mount; an attacker who can invoke statfs can trigger the expensive calls, but the recent patch limits the rate to two queries per second and returns cached results for subsequent calls, constraining the potential impact.
OpenCVE Enrichment
Debian DSA