Impact
The vulnerability stems from the Linux kernel’s tracing/user_events subsystem, where the dup_task_struct() function copies a pointer to a user event memory region into the child process without incrementing a reference count. If the subsequent allocation of that region fails, the child leaves the pointer unchanged. When the child exits, its cleanup routine frees the region it never owned, leaving the parent with a stale reference. This use‑after‑free can corrupt kernel memory, as observed by KASAN reports, and is classified as CWE‑825.
Affected Systems
Any Linux kernel build that includes the legacy tracing/user_events implementation prior to the upstream patch is affected. The CNA lists the product as Linux:Linux with no specific version range, so all kernels lacking the fix are considered vulnerable until updated. Systems running kernels with the tracing subsystem enabled and exposed to the relevant ioctl calls that allocate user events are at risk.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is high. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation. It is not listed in CISA’s KEV catalog. Local; an attacker must be able to fork a process or trigger the ioctl sequence that allocates the allocation failure or make the child exit while the parent still has the stale pointer. Successful exploitation could lead to kernel memory corruption and privilege escalation. The low EPSS suggests limited active exploitation currently.
OpenCVE Enrichment
Debian DSA