Impact
The vulnerability originates in the f2fs filesystem of the Linux kernel. A write to the critical_task_priority sysfs attribute updates the priority of checkpoint or garbage‑collection threads but the operation is not protected by the s_umount serialization lock, which protects other similar attributes. The race condition allows a concurrent remount or unmount to interfere with the update, potentially setting an invalid or unintended scheduling priority. The result is a denial‑of‑service by suspending or mis‑prioritizing essential background tasks.
Affected Systems
All Linux kernel releases that ship the f2fs filesystem without the patch that adds s_umount guarding for critical_task_priority writes are affected. This includes mainstream distributions' stock kernels as well as custom or older builds that have not applied the fix. The vendor list does not specify a specific distribution, so any distribution deploying f2fs in a kernel version prior to the patch is vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the attack would require an attacker with local access who can write to the f2fs sysfs file. The low EPSS score (<1%) and absence from the CISA KEV catalog indicate that exploitation is unlikely in the wild at this time. Still, the presence of a race condition in a core kernel subsystem justifies prompt patching, as the impact is a denial of service that could affect system stability.
OpenCVE Enrichment