Impact
In the Linux kernel a null pointer dereference occurs in hugetlb_cma_alloc_frozen_folio when a NULL nodemask is passed during allocation of a gigantic hugepage. The code dereferences the nodemask before confirming it is valid, triggering a kernel panic. An unprivileged user can exploit this by requesting a large hugepage with MPOL_PREFERRED_MANY on a system where Contiguous Memory Allocator (CMA) is enabled only on a subset of NUMA nodes, allowing a routine user process to bring the entire system down.
Affected Systems
All Linux kernel builds that contain the vulnerable path prior to the commit that fixed the nodemask handling. The faulted code is present in kernels that have not incorporated the patch referenced in the advisory. No specific version range is listed; thus any kernel before the referenced change is considered vulnerable.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. However, the flaw produces an immediate system‑wide denial of service, and because it can be triggered by ordinary user processes, the impact is high in shared or multi‑user environments. The attack vector is user‑space allocation of hugepages with MPOL_PREFERRED_MANY, requiring no special privileges.
OpenCVE Enrichment