Impact
The cuse module in the Linux kernel uses RCU callbacks to free resources. If the module is unloaded before the RCU grace period ends, the queued release callback runs against memory that has already been freed, causing a use‑after‑free. This results in a kernel page‑fault Oops; if the freed address later holds other data, the callback could execute unintended code in kernel space.
Affected Systems
Linux kernels that contain the cuse module and lack the commit adding an rcu_barrier() in cuse_exit are affected. All distributions shipping such unpatched kernels are susceptible, including common LTS releases and mainstream distributions.
Risk and Exploitability
The vulnerability has a very low estimated EPSS score of less than 1% and is not listed in CISA KEV, indicating a low likelihood of current exploitation. However, the impact is severe, as the use‑after‑free can cause a kernel crash or, if the freed memory is reused, arbitrary code execution in kernel mode. Exploitation requires the ability to unload the cuse module, which typically requires elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA