Impact
A flaw in the Linux kernel’s swap handling routine incorrectly frees a hibernation slot while a folio remains in the swap cache. This premature release can overwrite swap table entries that belong to unrelated data, leading to silent memory corruption, random process crashes, or data inconsistencies. The weakness is classified as CWE‑825, representing a missing or insufficient security control in system code.
Affected Systems
All Linux kernel distributions that include the unpatched swap handling code are affected. The issue is vendor‑agnostic and applies to any kernel build lacking the recent hot‑fix for the swap cache freeing logic. System administrators should check their current kernel version against the upstream fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known exploitation in the field. The likely attack vector is local: the problem triggers during hibernation or swap activity, especially when uswsusp prepares a hibernation image. An attacker would need to influence local swap usage or enable hibernation, potentially requiring elevated privileges. Without such conditions, the risk remains theoretical.
OpenCVE Enrichment