Impact
The Linux kernel flaw involves incorrect tracking of the page frame number during compound page population, causing the system to determine head or tail page mappings with a wrong PFN offset. This mis‑alignment can result in the kernel mapping incorrect memory pages, potentially leading to a kernel panic or other forms of memory corruption that abruptly halt services. The weakness is a logical error in pointer/index handling that compromises the integrity of the kernel’s memory manager.
Affected Systems
All Linux kernel releases that did not yet include the addr_pfn tracking fix are affected. Vendor information is limited to the Linux kernel and no specific version ranges are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high, though the EPSS score of less than 1% indicates a very low likelihood of widespread exploitation at present. The flaw is not listed in CISA’s KEV catalog. Because the issue lies within kernel’s memory allocation routines, a local attacker or any process that triggers compound page use could potentially exploit the bug, though it may require code execution at kernel level or privilege escalation to fully control the scenario. The attack vector is inferred to be local or within trusted kernel modules, as the bug operates during normal kernel memory management.
OpenCVE Enrichment
Debian DLA
Debian DSA