Impact
A race condition in the Linux kernel’s ftrace subsystem can cause a use‑after‑free when the directory for a trace instance is removed while an adjacent file (set_ftrace_filter or set_ftrace_notrace) is opened. The kernel then dereferences a freed ftrace_ops pointer, leading to a panic and crash. An attacker could use this to deny service on the affected host.
Affected Systems
All Linux kernel builds that include the ftrace debug filesystem and do not yet have the patch that protects the reference count of trace_array. Specific version information is not provided; any kernel compiled with the default debugfs configuration before the fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is less than one percent, suggesting low but non‑zero likelihood of exploitation, and the vulnerability is currently not listed in the CISA KEV catalog. Exploitation requires access to the trace instance files, which are normally restricted to privileged users, so the attack surface is limited to local or privileged attackers. Nonetheless, because of the kernel crash it is considered high risk until the fix is applied.
OpenCVE Enrichment