Impact
The vulnerability resides in the overlayfs subsystem of the Linux kernel. When the casefold consistency check fails during a directory creation, the cleanup routine end_creating() is invoked twice on the same dentry. The first invocation releases the parent directory’s i_rwsem and releases the dentry reference. The second invocation attempts to release a lock that was never held and drops a reference that was never acquired, resulting in the parent directory becoming permanently locked. Subsequent attempts to create or access files under that directory block indefinitely, effectively wedging the overlay mount. The flaw does not provide any privilege escalation, data disclosure, or code execution; it is strictly a local denial-of-service condition confined to the overlay filesystem.
Affected Systems
All Linux kernel releases that include overlayfs prior to the merge of the commit that removed the double end_creating() call are affected. Overlayfs is present in the default kernels of most mainstream Linux distributions. Any system that can mount an overlay filesystem with casefolding enabled is potentially impacted unless the kernel has been updated by an unprivileged user who can create a mount namespace and perform the overlay mount, as demonstrated by the example that uses unshare and mount commands.
Risk and Exploitability
The CVSS score of 7.8 denotes a high impact, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The attack is local and requires only the ability to mount an overlay filesystem; no special privileges are needed beyond the ability to create a mount namespace. The risk is that a single unprivileged process can cause a permanent lock on the parent directory, blocking all future creation operations under that mount. Although the vulnerability is not listed in the CISA KEV catalog and no widespread exploits have been observed, the potential for service disruption is significant, especially in environments that rely heavily on overlay filesystems.
OpenCVE Enrichment