Impact
In the Linux kernel, a flaw in the handling of guest debug watchpoints results in an old_data buffer leak. When a KVM_SET_GUEST_DEBUG request fails after some watchpoints have been successfully imported, the cleanup routine releases the wp_info array but not the old_data buffers that were allocated for the successful entries. Each failed request can leak up to MAX_BP_COUNT‑1 buffers of up to MAX_WP_SIZE bytes of memory, and this process can be repeated an arbitrary number of times, potentially exhausting kernel memory and causing a denial‑of‑service condition for the hypervisor host.
Affected Systems
The affected product is the Linux kernel. No specific kernel version is listed, so any kernel that has not yet applied the patch is potentially vulnerable.
Risk and Exploitability
The EPSS score for this vulnerability is below 1 % and it is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The attack requires privileged access to the Kernel‑Virtual‑Machine (KVM) interface to issue KVM_SET_GUEST_DEBUG requests, so it is a local or privilege‑escalation vector rather than a remote network attack. If an attacker can repeatedly issue failing watchpoint configurations, they can force the kernel to leak memory until the hypervisor runs out of resources, resulting in a service disruption.
OpenCVE Enrichment
Debian DLA
Debian DSA