Impact
In the Linux kernel, the memory‑management function shrink_lruvec() does not report a quiescent state for RCU‑tasks on PREEMPTION kernels when cond_resched() is a no‑op. During page reclamation the function stalls, leaving RCU tasks in a holdout state and preventing the kernel from freeing pages. This can lead to increased memory pressure and degraded system performance, potentially causing application or system instability due to exhausted resources. The vulnerability is a Resource Exhaustion flaw (CWE‑821) and does not provide direct remote code execution or authentication bypass.
Affected Systems
The defect is present in the Linux kernel source, meaning all distributions and vendors shipping an unpatched kernel contain it. Any kernel version that still uses the old shrink_lruvec() implementation is potentially affected until the upstream patch that replaces cond_resched() with cond_resched_tasks_rcu_qs() is applied.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and the EPSS score is below 1 percent, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local kernel code execution, requiring the attacker to have kernel privileges or to deliver a payload that forces high memory reclamation activity. Based on the description, it is inferred that an adversary would need local access on the host to exploit the flaw. In the absence of such access the impact on stability warrants remediation.
OpenCVE Enrichment
Debian DSA