Impact
A use‑after‑free flaw exists in the Linux kernel’s ring buffer tracing subsystem when the sub‑buffer order is changed while a reader holds a pointer into an event. The reader may dereference freed memory, potentially corrupting kernel memory or leaking sensitive data. This is a classic use‑after‑free weakness classified as CWE‑825.
Affected Systems
All hosts running a Linux kernel that lacks the patch introduced by commit 05ebe1e1d7d38c sub‑buffer reordering, are affected. The bug appears in any distribution using the affected kernel source.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild, and the vulnerability is not listed in CISA KEV. Attack requires a local process with write access to buffer_subbuf_size_kb to trigger the race while a trace_pipe reader is active, which typically means the attacker must have kernel or root privileges. The consistent use of a privileged operation and the nature of the race make it more of a local exploitation vector than a public remote attack.
OpenCVE Enrichment
Debian DSA