Impact
A missing SRCU grace period in the NVMe namespace allocation error path causes the namespace structure to be freed while a reader may still be accessing it. This results in a classic use‑after‑free condition that can corrupt kernel memory and potentially allow an attacker to execute arbitrary code with kernel privileges.
Affected Systems
Any Linux system running a kernel version that contains the vulnerable NVMe code prior to the commit that introduces the SRCU grace period is affected. This includes distributions that have not yet applied the patch identified by commit 76023560d60f10b4f808941163aa2975f1631683. All Linux kernels with a vulnerable NVMe driver are at risk.
Risk and Exploitability
The CVSS score of 9.8 reflects a severe impact. The EPSS score of less than 1% indicates a low probability of current exploitation, yet the kernel‑level nature makes any successful exploit highly damaging. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack could be local, but a remotely‑targeted attack might be possible if an attacker can trigger the NVMe driver via a network protocol such as iSCSI or RDMA that feeds malicious NVMe commands to the device. Successful exploitation would likely require precise timing to achieve the race condition between the error path and concurrent readers.
OpenCVE Enrichment