Impact
The vulnerability is a use‑after‑free in the Ceph integration of the Linux kernel. An iteration over a list of cap‑flush structures can dereference a structure that has already been freed by a concurrent thread. This flaw can cause the kernel to crash, leading to a denial of service on the affected node. The flaw is classified as CWE‑366.
Affected Systems
The issue resides in the Linux kernel’s Ceph subsystem. No specific kernel version range is enumerated in the advisory; therefore any kernel that contains the pre‑fix code is potentially vulnerable. Users should verify that their kernel includes the commit that secures the list iteration, such as the downstream revisions that incorporate the upstream patch commit identified in the advisory.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of < 1% indicates a very low probability of exploitation. It is not listed in CISA KEV. Because the race depends on a specific ordering between __kick_flushing_caps and handle_cap_flush_ack, successful exploitation would likely require a prepared kernel module or privileged process. Overall, the risk remains moderate but the impact of a kernel panic could disrupt services.
OpenCVE Enrichment
Debian DSA