Impact
BTT reads the arena’s nfree field from the medium without validating it. When an arena reports a nfree value that is lower than the number of lanes, the freelist and rtt arrays are allocated too small for the indices used during zone acquisition. This causes an out‑of‑bounds write beyond the allocated buffer, corrupting kernel memory. The resulting corruption can crash the system, corrupt data structures, or provide a foothold for privilege escalation.
Affected Systems
All Linux kernel builds that deploy the NVDIMM/BTT subsystem prior to the commit that added nfree validation are affected. This includes any system that loads the BTT driver and supports persistent memory arenas, regardless of distribution or kernel version, until the patch is applied.
Risk and Exploitability
The CVSS base score of 7.8 indicates serious impact if successful. The EPSS score is less than 1 %, and the vulnerability is not yet listed in CISA’s KEV catalog, meaning no known active exploitation in the wild. However, the vulnerability can be only exercised when a malicious or improperly configured NVDIMM device is presented to the running kernel, so a local or privileged attacker with access to the hardware can trigger the out‑of‑bounds write.
OpenCVE Enrichment
Debian DLA
Debian DSA