Impact
The vulnerability occurs in the Linux kernel when the integrity audit subsystem processes a pathname that exceeds the buffer limit. The helper function dentry_path() returns an error encoded as a pointer (ERR_PTR(-ENAMETOOLONG)) which the validate_hash_algo() routine passes straight to integrity_audit_msg() without checking for errors. The audit message routine then treats the error pointer as a valid string and calls strlen() on it, causing a page fault and the kernel to panic. The crash precludes the system from maintaining normal operation and can be triggered by providing a specially crafted file name during inode attribute set operations, leading to a denial‑of‑service condition. Affected systems This flaw affects all Linux kernel builds that include the IMA integrity audit feature, specifically any kernel that has not applied the patch referenced in the supplied Git revisions. The vulnerability is present in the Linux kernel source tree and is active in the environment described. Vendors that ship Linux kernel binaries without the patch are impacted, regardless of the distribution or kernel version. Risk and exploitability The CVSS details are not explicitly reported, but the EPSS score is listed as less than 1%, indicating a very low to negligible exploitation probability at the time of analysis. However, the impact of a successful exploit is severe, causing a kernel panic and reboot. The risk is therefore high in environments where the audit feature is enabled and where an attacker can influence the creation or modification of files with excessively long names. The vulnerability is not currently listed in the CISA KEV catalog, so there is no confirmed widespread exploitation yet, but the potential for a local privilege escalation or data corruption remains.
Affected Systems
Linux kernel installations that include the Inode Mount Audit (IMA) subsystem, specifically any build prior to the patch commits referenced in the provided Git URLs. All vendors shipping standard Linux kernels without this patch are affected.
Risk and Exploitability
The flaw carries a high impact if triggered, but the EPSS score of <1% suggests that exploitation is unlikely to occur in the wild at this time. The vulnerability is not in the CISA KEV list, so no public exploits are documented. The attack would require local interaction or low‑privileged code that can perform an inode setxattr operation with a path exceeding the buffer.
OpenCVE Enrichment
Debian DLA
Debian DSA