Impact
The vulnerability arises in the function check_new_map() that accesses a session structure after releasing a mutex. Because the code fails to hold an additional reference before unlocking, another thread can unregister and free the session while the first thread still holds a reference, leading to a use‑after‑free (CWE‑364). This unexpected resource release can corrupt kernel memory, cause system crashes, and potentially allow an attacker to execute code in kernel context.
Affected Systems
The affected systems are Linux kernel installations that include the buggy Ceph module. The CVE references point to the upstream Linux kernel source tree, indicating that the flaw exists in the kernel itself and can affect any derivative that has not applied the subsequent patch. No specific version information is provided, so any kernel with the relevant Ceph code may be vulnerable until patched.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical. The EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV. The flaw involves a race condition that can cause a use‑after‑free in the Ceph module of the Linux kernel. While the description does not specify an explicit attack vector, a race condition of this type generally requires concurrent kernel activity and manipulation of kernel data structures, which would typically be achievable only with local or privileged access.
OpenCVE Enrichment