Impact
A flaw in the Linux kernel’s fscrypt integration allows ceph messenger to pass buffers allocated from the vmalloc region to a decryption routine that expects linear memory. This mismatch causes an oops, leading to a kernel crash with no elevated privileges. The effect is that any system running a vulnerable kernel can be forced into a denial‑of‑service condition, potentially disrupting all user processes.
Affected Systems
All Linux kernel installations are susceptible because the issue is tied to the core fscrypt subsystem. No specific version range is listed in the available data, so a check against local kernel sources and the patch logs is required.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical impact and wide exploitation potential. The EPSS score is listed as < 1%, meaning the probability of exploitation is low at present, and the vulnerability is not in the CISA KEV catalog. The likely attack vector is a local kernel exploit through ceph communication, as the problem occurs when the messenger client creates messages that land in the vmalloc region. A local attacker could trigger the oops by interacting with ceph or by controlling memory layout to force allocation into the problematic region.
OpenCVE Enrichment
Debian DLA
Debian DSA