Impact
In the Linux kernel, a flaw in the memory control group (memcg) subsystem causes folio migration across NUMA nodes to violate a core assumption that a folio’s object cgroup (objcg) matches its node. The resulting desynchronisation between objcg reparenting and LRU list splicing creates a race condition that can corrupt kernel memory structures and, in the worst case, lead to a crash or arbitrary code execution. The vulnerability is a conflict of locks: an LRU operation may lock the wrong memcg, allowing an attacker to craft a scenario where kernel data is mis‑managed.
Affected Systems
All Linux kernel builds that include the memcg reparenting code are affected. Because the version information is not specified, any system running a Linux kernel prior to the application of the patch that fixes the mis‑synchronisation is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks this issue as high severity, yet the EPSS score of less than 1% indicates that the likelihood of an observed exploit is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an actor to force a folio to migrate across nodes while LRU operations occur, which could be achieved through high memory pressure or by running memory‑intensive code that triggers page migration. Although this is not trivial, the potential for kernel corruption warrants timely remediation.
OpenCVE Enrichment