Impact
In the Linux kernel’s audit subsystem, audit_del_rule() drops a temporary tree reference during filesystem notification autoremove. The unconditional audit_put_tree() call assumes a template case, but for rules that mix AUDIT_DIR and AUDIT_EXE types, the autoremove removes the live tree reference. Repeated autoremove events can free a tree that other audit rules still reference that can corrupt memory and potentially crash the kernel. This weakness is classified as CWE‑825.
Affected Systems
All Linux kernel packages that include the unpatched audit framework code before the patch backports or patches beyond the commit itself are affected.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical. The EPSS score of under 1% indicates a low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged user who can add or remove audit rules. Repeatedly deleting mixed AUDIT_DIR and AUDIT_EXE rules can trigger the use‑after‑free, potentially causing a kernel crash or memory corruption.
OpenCVE Enrichment
Debian DSA