Impact
This vulnerability in the Linux kernel allows a NULL pointer dereference when the ckpt_thread_ioprio sysfs attribute is written while checkpoint_merge is enabled and the checkpoint thread is not running. The dereference occurs on cprc->f2fs_issue_ckpt when it is NULL, leading to a kernel panic. The impact is a denial of service for the local system, as the crash terminates all running processes and requires a reboot. The weakness is a classic NULL pointer dereference identified by CWE‑476.
Affected Systems
The defect exists in the Linux kernel for all distributions that include the f2fs filesystem driver. The affected code path is part of the ckpt_thread management in f2fs. No specific kernel release is listed, so any kernel version containing the unpatched ckpt_thread_ioprio sysfs write is vulnerable, which includes mainstream releases in 2026.
Risk and Exploitability
The Enterprise Package Security Score (EPSS) for this issue is listed as under 1%, indicating a very low probability of exploitation. It is not listed in the CISA Known Exploited Vulnerabilities catalog (KEV), so no public exploit has been documented. The vulnerability requires local write access to the sysfs attribute controlling checkpoint merge, which typically requires root privileges or an unprivileged user with permission to write directly to sysfs. The attack vector is therefore likely local, but a malicious process with sufficient privileges can crash the host. The severity is ambiguous due to missing CVSS data, but the potential for an imminent kernel crash warrants immediate patching.
OpenCVE Enrichment
Debian DLA
Debian DSA