Impact
The Linux kernel’s tracing subsystem contains a flaw where event_test_stuff() unconditionally passes the task_struct pointer returned by kthread_run() to kthread_stop() without validating the return value. When kthread_run() fails, it returns an error pointer such as ERR_PTR(-ENOMEM). Passing this error pointer into kthread_stop() causes a dereference of an invalid pointer and results in a kernel crash. The weakness is a classic unchecked return value leading to a null pointer dereference. An attacker exploiting this flaw would trigger a kernel panic, thereby denying service to the system. This flaw is a classic example of CWE-476: Unchecked Return Value Leading to Null Pointer Dereference.
Affected Systems
All Linux kernel releases that do not contain the patch adding a null-pointer check before calling kthread_stop() are potentially vulnerable. The CNA data associates the defect with the Linux kernel as a whole; specific version ranges are not provided, so any kernel prior to the commit that implements the fix is at risk.
Risk and Exploitability
With a CVSS score of 4.4 and an EPSS score of less than 1%, the exploitation likelihood is low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local privileged access that can trigger the boot-time self-test or otherwise execute the vulnerable path. An attacker would need to force a pressure during boot, or reach event_test_stuff(). The impact, if exploited, would result in a kernel panic and denial of service.
OpenCVE Enrichment
Debian DSA