Impact
The vulnerability is a use‑after‑free flaw in the Linux kernel's KVM subsystem. During lockless read‑only rmap walks, the code may read stale rmap entries after a writer frees the underlying memory, allowing an attacker to trigger a kernel memory corruption. An attacker could exploit this to execute arbitrary code as the privileged host, effectively causing a kernel‑level privilege escalation.
Affected Systems
The flaw affects all Linux kernel releases that run KVM with the CONFIG_KVM_MMU_LOCKLESS_AGING option enabled, as the bug is triggered only in that configuration. Since the affected products are listed generically as Linux kernel, any distribution that includes a KVM implementation with this configuration may be vulnerable; the specific version range is not provided in the CVE data.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to access the KVM environment, likely from a guest VM, and obtain control over memory referenced by the rmap to trigger the use‑after‑free. The lack of serialization between readers and writers during aging walks makes the flaw exploitable under normal scheduling conditions.
OpenCVE Enrichment