Impact
A flaw in the kernel’s ttm_pool_restore_and_alloc routine leaves the tt->restore flag set after a successful restore, causing subsequent backup or restore flows to believe a restore has already finished while shared‑memory handles remain in use. This stale state can trigger a kernel crash (Oops) and thus cause a denial of service. The vulnerability is tied to CWE‑665 (Improper Initialization) and has a CVSS base score of 7.8.
Affected Systems
The issue exists in all Linux kernel versions that do not include the patch commits 941ac10529b3be5965a88d432a161ab459672ba8 and a46ab76b6cf5478e2ac7b942a377c7a1827b436a. The affected vendor product is the generic Linux kernel; no specific version ranges are supplied, so any kernel before the fix is vulnerable. Systems running a distro kernel not yet updated to incorporate those commits are at risk.
Risk and Exploitability
With an EPSS score of <1 % and no listing in the CISA KEV catalog, the likelihood of real‑world exploitation is low. Attackers would need local or privileged access to trigger the faulty backup/restore code path, so the exploitability is limited. The likely attack vector is local or privileged code execution. Nevertheless, the high impact of a kernel crash warrants immediate attention. Apply the updated kernel as soon as possible to eliminate the dangling tt->restore flag and prevent service disruption.
OpenCVE Enrichment