Impact
This vulnerability resides in the DRM pagemap subsystem of the Linux kernel. The function drm_pagemap_migrate_populate_ram_pfn() mishandles higher‑order folio allocation by not using the __GFP_NOWARN flag, causing allocation failures to spam the log. Furthermore, if the high‑order allocation fails, the code incorrectly falls back to order‑0 allocations, leaving compounding bits unset for the affected PFNs. In the free_pages error path, the code calculates the folio order after releasing the page reference, resulting in a use‑after‑free when that reference was the last one. These flaws can cause a kernel panic or corruption of the DRM memory mapping.
Affected Systems
The affected product is the Linux kernel itself. Any distribution running a kernel that contains the legacy DRM on‑demand folio handling before the patch (commits 10e92e18 and df72e55) is vulnerable. Because the GNU version of kernel is listed, all vendors that ship a kernel containing these code paths are impacted until they deploy the fix.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, and the EPSS score of less than 1% suggests that exploitation attempts are currently rare in the wild. The flaw is not listed either in the CISA KEV catalog. An attacker would need local access to a DRM device or code that triggers the pagemap migration paths. Successful exploitation could result in a kernel crash, which may provide a local privilege escalation path through a subsequent reboot or misuse of the system. Thus, the primary risk is denial of service with a potential for privilege escalation if the attacker gains sufficient local privileges.
OpenCVE Enrichment