Impact
The Linux kernel contains an issue in the NTFS driver where the function kmap_local_page() is used incorrectly during compressed I/O paths. When a high‑memory page is mapped, the driver discards the address returned by kmap_local_page() and later accesses or unmapped the page using page_address(), which is invalid for high‑memory pages. This misuse can lead to kernel memory corruption, crashes, or other unintended behaviors. The patch replaces the unsafe local mapping usage with safer helper functions such as memcpy_from_page(), memcpy_to_page(), and memzero_page(), preventing the potential for corrupted memory states.
Affected Systems
The vulnerability affects the Linux operating system, specifically the Linux kernel. No specific kernel versions are listed in the data, so any kernel revision prior to the applied fix that contains the unpatched NTFS driver code could be impacted.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in CISA KEV, indicating a very low known exploitation probability. Although no CVSS score is provided, the nature of the flaw suggests a local kernel exploitation path, potentially resulting in local privilege escalation or denial‑of‑service if an attacker can write or manipulate NTFS filesystem data. Exploitation would require local access or a scenario where an attacker can trigger the affected compressed I/O path. The likely attack vector is a local kernel exploitation scenario involving NTFS operations.
OpenCVE Enrichment