Impact
The flaw resides in the Ceph integration of the Linux kernel. A logic defect caused the cap‑reclaim workqueue to repeatedly re‑enqueue itself when ceph_trim_dentries() returned -EAGAIN but no resources were freed. The result is a busy loop that consumes CPU cycles without making progress, leading to denial of service through resource exhaustion. The weakness is an example of Infinite Loop or Resource Exhaustion, classified as CWE‑835.
Affected Systems
All Linux distributions that ship a kernel prior to the upstream patch addressing ceph_trim_dentries() will be affected. The issue is limited to systems running the legacy Ceph lease reclamation code path in the kernel; any distribution that has upgraded to a kernel release including the fix is immune. Administrators should determine whether their kernel version contains the patched logic and whether their Ceph cluster configuration enables cap‑reclaim activity.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity denial of service potential The EPSS score of <1% denotes a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to trigger the Ceph lease reclamation path—such as by performing file operations that invoke lease handling The attack vector is therefore presumed to be local or on a Ceph cluster with authenticated control. Because the impact is limited to resource exhaustion and no privilege escalation or data compromise is possible, the risk is significant only to impacted hosts executing the busy loop, and active exploitation appears unlikely at present.
OpenCVE Enrichment
Debian DSA