Impact
The vulnerability originates in the kernel’s debugfs handling. When the system is operating in integrity lockdown mode, kernel data is protected by blocking certain file operations. The lockdown check was expanded to include the old mmap operation but did not also consider mmap_prepare. Because some files use allowing an attacker to read or manipulate debugfs data that should be inaccessible when lockdown is active.
Affected Systems
The flaw affects Linux kernels that have the lockdown feature compiled in and that mount a debugfs file system. No explicit vendor or version list is supplied in the advisory; therefore, any kernel build that has not yet incorporated the patch to apply the mmap_prepare check remains vulnerable. The damage is limited to systems running a debugfs mount point under lockdown. If a custom build omits the patch, that build is also affected.
Risk and Exploitability
The CVSS score of 4.4 reflects a moderate severity level. The EPSS score of less than 1% indicates a very low probability that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local, requiring the attacker to have the ability to invoke mmap_prepare against a debugfs file; remote exploitation would be. If exploited successfully, an attacker can read or modify privileged debug information that should be hidden by lockdown mode, compromising kernel integrity and potentially enabling further attacks.
OpenCVE Enrichment