Impact
The flaw lies in backing_file_open() deriving a backing file’s path from the f_path of the user file, which is incorrect when the user file is itself a backing file, such as in nested overlayfs. This causes the kernel to record an impossible, disconnected path in /proc/<pid>/maps and perf/ftrace tables. The weakness is a path‑confusion error (CWE‑41) and does not open avenues for code execution or privilege escalation.
Affected Systems
Affected are Linux kernel systems that implement overlayfs, fuse passthrough, or erofs when nested overlayfs mounts are employed. Kernels that have not incorporated the commit that re‑introduces the issue are vulnerable; the specific version threshold is not stated in the data.
Risk and Exploitability
With a CVSS score of 2.3 and an EPSS below 1 %, the risk is considered low. The vulnerability is not listed in CISA KEV, and exploitation would require local kernel access and is limited to manipulating or observing diagnostic output rather than achieving remote code execution. No known attack vector beyond local observation is documented; it is inferred that the attack vector is local only because kernel path manipulation is confined to the host.
OpenCVE Enrichment
Debian DSA