Impact
In the Linux kernel, the ffs_epfile_write_iter and ffs_epfile_read_iter input–output functions may free an io_data structure while an AIO cancel handler still references it. When a cancellation occurs after the free but before the pointer is cleared, the cancel routine dereferences a dangling pointer, creating a use‑after‑free that can be leveraged for arbitrary code execution. The flaw is a classic use‑after‑free weakness (CWE‑416).
Affected Systems
The vulnerability affects all Linux kernel deployments that have not applied the corrective commit. No specific kernel versions are listed in the vulnerability data; any running kernel without the patch is potentially exposed.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high‑severity flaw, and the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is a local kernel race; an attacker with the ability to trigger AIO operations and cancellation on a target system could achieve privilege escalation or arbitrary code execution. The vulnerability is not present in the CISA KEV list, but the kernel nature means that any unpatched system remains a risk until the kernel is updated.
OpenCVE Enrichment
Debian DLA
Debian DSA