Impact
A bug in mm/mglru of the Linux kernel allows unevictable folios to be incorrectly handled during sorting. The faulty shortcut leaves the mlock_count field aliased to a list poison value, which is interpreted as a large numeric count. As a result, pages that should be reclaimable stay flagged as unevictable, inflating the kernel’s memory accounting and preventing those pages from being evicted. The bug can also reorder LRU flag updates, creating race conditions that may cause pages to be prematurely removed from generation lists, leading to unpredictable memory management behavior. The overall impact is potential memory exhaustion and degradation of system performance.
Affected Systems
All Linux kernel builds that do not include the upstream commit which removes the redundant unevictable folio handling are impacted. The affected products are identified as Linux:Linux, covering all distributions shipping an unpatched kernel. Once the patch is applied, the vulnerability is eliminated.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range. The EPSS score of <1% indicates a very low exploitation probability and it is not listed in CISA KEV. The most probable attack vector is local to the system, inferred that an attacker with the ability to invoke mlock() and munlock() could repeatedly lock and unlock pages, causing the kernel to continually inflate the mlock_count field and exhaust free memory over time. The lack of a high EPSS score suggests that widespread exploitation is unlikely.
OpenCVE Enrichment