Impact
The ecryptfs subsystem in the Linux kernel fails to release a message context when a send to the userspace daemon fails. The context remains allocated on the ecryptfs allocated list, preventing reuse and eventually exhausting the available context pool. This resource leak can cause the ecryptfs filesystem to become unusable, constituting a denial‑of‑service condition. The weakness is recognized as a resource leak (CWE‑772) and does not directly threaten confidentiality or integrity.
Affected Systems
Any Linux kernel build that includes the ecryptfs module is affected. The vulnerability is present in the kernel source starting with the commit that introduced the bug and remains until patched. All distributions that ship a kernel with ecryptfs compiled (for example most mainstream distributions) fall under this scope, regardless of whether the module is enabled at boot or loaded dynamically.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, classifying it as high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Exploitation would likely require a local or privileged user able to repeatedly trigger ecryptfs send failures, such as by interacting with the userspace daemon or manipulating file operations that invoke ecryptfs_send_miscdev. The impact is purely availability; no confidentiality or integrity impact is afforded. Given the high severity and low exploitation probability, system administrators should treat this as a high priority update.
OpenCVE Enrichment
Debian DSA