Impact
The vulnerability arises when a Linux kernel module initialization fails after creating procfs entries and per‑CPU counters. The failure path incorrectly releases only post‑procfs resources and then aborts by calling class_unregister(), leaving the proc tree and its counters in an allocated state. This leak can consume kernel memory or expose dangling kernel pointers, potentially causing a denial‑of‑service or allowing further exploitation by a privileged attacker.
Affected Systems
All Linux kernel builds are affected, as the issue exists in the core smb/server subsystem. No specific kernel versions are enumerated in the CVE data; any build that includes this code path is potentially impacted.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation in the wild. The vulnerability requires a kernel module init failure, which typically demands elevated privileges or the ability to load custom kernel modules. If successfully triggered, the resulting resource leak could lead to system instability or memory exhaustion, but the attack surface stays restricted to environments where the attacker can influence kernel module loading.
OpenCVE Enrichment