Impact
The vulnerability resides in the Linux kernel’s mm/pagewalk module. A stale walk->action value of ACTION_AGAIN can persist during a split or refault and, when walk_pmd_range() re‑enters, it incorrectly retries the PMD in an triggers an out‑of‑bounds write in __mincore_unmapped_range(). The flaw is a bounds‑write weakness (CWE‑787) exercised by privileged kernel code, as described.
Affected Systems
Any Linux kernel build that contains the upstream source prior to the patch that fixes walk_pmd_range() handling is vulnerable. The fix is introduced in commit 895cd4ecbb2e03d7583103c65ee5adaae126ed6d or later; kernels lacking that commit – i.e., versions before the patch – are at risk; kernels updated after that commit are considered safe.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS indicates a very low probability of exploitation, with an EPSS of < 1%. The issue is not listed in CISA’s KEV catalog,. The CVE description does not specify an exploitation scenario or attacker privilege level, but the vulnerability involves privileged kernel code. The overall risk for hosts running unpatched kernels remains.
OpenCVE Enrichment