Impact
The vulnerability arises when parsing block layout configurations in the Linux kernel. If a child device fails to parse, the failed entry is omitted from the child count but the associated device array is not freed. This results in a memory and resource leak that can gradually exhaust kernel resources, potentially causing system instability or a crash. In addition, the bl_parse_scsi() helper can drop a file reference and later leave the pointer dangling, which may trigger a double release and lead to a kernel panic. The primary impact is a denial of service through resource exhaustion or direct corruption of kernel memory.
Affected Systems
The flaw affects the generic Linux kernel when the pnfs/blocklayout subsystem is active. No specific version list is supplied; any distribution that has not yet incorporated the commit patches is vulnerable.
Risk and Exploitability
The EPSS probability of exploitation is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the potential for a kernel panic and resource exhaustion signals a high severity if the flaw is triggered. The attack vector is inferred to be through a malformed block layout request or a corrupted Pnfs configuration, likely originating from a privileged user or malicious client. Due to the low perceived exploitation probability, the risk remains moderate, but the consequences warrant prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA