Impact
During rehashing of a hash table under read-side critical section, a memory allocation request that can block is performed. The kernel mistakenly hardcodes the allocation flag GFP_KERNEL for a temporary weights array when the task has a weighted interleave memory policy. This causes a sleeping allocation inside an atomic or RCU context, leading to a potential kernel panic and system instability. The flaw does not provide direct remote code execution but can disrupt service by crashing the kernel, which is a severe impact on availability.
Affected Systems
The vulnerability affects the Linux kernel core, including all distributions running the affected kernel versions. No explicit version range is listed, so any kernel that contains the unpatched behavior is at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high risk, but the EPSS score of less than 1% suggests that exploitation is unlikely under current conditions. The bug is not listed in CISA’s KEV catalog, implying no known widespread exploitation. Attacks would require triggering kernel hash table rehash operations, which are generally part of normal kernel functionality and not easily controllable by external actors. Consequently, the risk is high but the exploitation probability is low, and the vulnerability primarily threatens local or system-wide availability.
OpenCVE Enrichment
Debian DLA
Debian DSA