Impact
In the Linux kernel the null_blk module can leak memory and kernel resources when its initialization fails. During boot the module allocates a global tag_set for block I/O tagging. If the subsequent device creation fails, the cleanup routine improperly omits freeing this global tag_set, resulting in a permanent memory leak. The leaked tag_set occupies kernel memory and its internal maps, which can grow unbounded over time and degrade system performance or lead to a complete memory exhaustion, effectively causing a denial of service.
Affected Systems
The vulnerability is present in the Linux kernel, affecting all distributions that ship a kernel module named null_blk. No specific kernel version range is listed in the advisory, so kernels prior to the patch referenced in the advisory are considered affected.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The exploitation requires code executed in kernel mode, typically as a local privileged attacker or a malicious module loader. The primary risk is a local denial of service; remotely-triggered exploitation would be limited by the need for kernel module loading privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA