Impact
A use‑after‑free condition exists in the Linux kernel kprobe subsystem when the blacklist list is walked without holding the kprobe_mutex lock. During module unload, blacklist entries are removed and freed with kfree, but a concurrent traversal may dereference the freed memory, corrupting kernel structures and potentially allowing an attacker to execute arbitrary code with kernel privileges.
Affected Systems
The flaw affects the Linux kernel in general; any kernel lacking the RCU protection commit for kprobe_blacklist is vulnerable. No specific version range is listed, so a review of release notes for the RCU‑based patch is required to confirm whether a deployment is affected.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is deemed high severity. The EPSS score of less than 1% indicates a very low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, the attack vector is local, requiring an actor capable of loading or unloading kernel modules. Exploitation would depend on precise timing of probe activity and module unloading to trigger the use‑after‑free during a concurrent kprobe traversal.
OpenCVE Enrichment
Debian DLA
Debian DSA