Impact
A bug in the Linux kernel’s DMA direct allocation helper caused dma_direct_alloc_from_pool() to return an improper CPU address instead of a struct page pointer. The mismatch leads to incorrect handling of page pointers during DMA allocation, which in turn can corrupt kernel memory or trigger a panic. The issue was exposed when drivers or code paths calling dma_direct_alloc_pages() interacted with the faulty helper, allowing the kernel to reference invalid memory locations.
Affected Systems
The vulnerability affects the Linux kernel, however no specific release dates are listed in the advisory. Any kernel versions compiled before the fix that still use the dma_direct_alloc_from_pool() helper are potentially impacted. The patch was integrated by committing the change in the upstream repository, so any kernel built from a tree after the commit 5b138c534fda should be safe.
Risk and Exploitability
The CVSS score of 8.8 marks it as high severity, but the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires the attacker to influence a privileged process that can trigger the faulty DMA allocation path, so the attack vector is local with kernel-context privileges. An attacker who can execute code in the kernel may be able to trigger memory corruption or a panic, but the narrow conditions and low exploitation probability reduce the overall risk.
OpenCVE Enrichment
Debian DLA
Debian DSA