Impact
In the Linux kernel’s iomap subsystem, a null pointer dereference occurs when the code attempts to free an integrity payload that was never allocated because block device PI verification is disabled. This flaw can crash the kernel during of service. The weakness is an improper null check classified as CWE‑476.
Affected Systems
All Linux kernel builds that lack the corrective commit patch are vulnerable, covering every distribution that ships an unpatched kernel version. Specific version ranges are not enumerated in the advisory, so any kernel not containing the fix should be considered exposed.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability is exploitable locally by triggering a sync read on a block device configured with PI verification 4.7 reflects moderate severity, and the EPSS score of <1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active attacks. loss of system availability.
OpenCVE Enrichment