Impact
The kernel’s kmemleak scanner walks every task’s stack inside a single RCU read lock without a reschedule. On hosts with a very large number of threads, especially those running debug features such as KASAN or lockdep, this loop can consume a CPU core for extended periods and trigger the kernel watchdog to report a soft lockup. The resulting symptoms are a hung CPU and degraded system operation, effectively denying useful service to legitimate users. The vulnerability does not provide remote code execution or data disclosure but could be exploited if an attacker can create an excess of concurrent tasks to trigger the lockup. The likely attack vector is inferred from the description as an attacker creating many user‑space threads to trigger the kmemleak scan, leading to a soft lockup.
Affected Systems
All Linux kernel builds that contain the kmemleak scanning routine before the patch series v3 are affected. The vendor product is Linux: Linux. The vulnerability applies to kernel versions that have not yet applied the patch that walks tasks with find_ge_pid() and introduces early stopping; systems with many concurrent kernel threads or with KASAN/lockdep enabled are most at risk.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and because the EPSS score is less than 1%, the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The patch mitigates the risk by limiting the size of each RCU critical section and allowing the scheduler to run between tasks, thereby preventing a soft lockup when the scan runs on systems with many threads or debug features that prolong the scan duration. Based on the description, it is inferred that the vulnerability can be triggered by forcing the kernel to perform extensive task stack scans, such as by spawning a large number of processes or enabling specific debugging facilities.
OpenCVE Enrichment
Debian DSA