Impact
The flaw in the Linux kernel causes the system to incorrectly process non‑present, device‑private PMDs when queueing folios, which can lead to kernel panics, VM_BUG_ON, or oops. The weakness is classified as CWE-824.
Affected Systems
The issue is present in the Linux kernel; no specific release not applied the patch in the 3‑commit series will be affected. Users with HMM‑based GPU drivers that migrate huge pages to device memory are especially at risk.
Risk and Exploitability
CVSS score 7.8 indicates high severity. EPSS score < 1% and the vulnerability is not in the CISA KEV catalog. The likely attack vector is through local userspace calls such as mbind(), migrate_pages(), or set_mempolicy_home_node() on ranges that have device‑private huge pages, which an attacker could exploit to trigger a kernel oops and cause denial of service. No remote exploitation is documented.
OpenCVE Enrichment