Impact
The flaw is triggered when the Linux kernel attempts to acquire a spinlock during a Non‑Maskable Interrupt on a single‑processor configuration. The kernel incorrectly calls spin_trylock() in this context, which can lead to a crash or deadlock when the free_pages_nolock path is exercised. A local attacker can exploit this by executing a BPF program or other tracing code that uses the affected allocation routines while an NMI is pending, causing a system crash and potentially enabling privilege escalation.
Affected Systems
The vulnerability exists in all Linux kernel releases that support non‑SMP (UP) builds prior to the patch series “mm/page_alloc: fixes for free_pages_nolock() on RT/UP.” It affects every vendor that ships the kernel for single‑processor systems. Versions older than the patch are considered vulnerable; no specific version numbers are supplied in the data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 %, suggesting that exploitation is technically possible but unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require local access, likely via a privileged user or a compromised application that can load malicious BPF code. The attack vector is local, and while the probability of exploitation is low, the impact of a kernel crash and privilege escalation is severe.
OpenCVE Enrichment