Impact
The vulnerability involves a memory leak in the Linux kernel’s SCSI midlayer. When the scsi_alloc_sgtables() routine fails after an sd_set_special_bvec() call, the special payload page allocated for UNMAP and WRITE SAME commands is not freed because uninit_command() is not invoked and the RQF_SPECIAL_PAYLOAD flag is not cleared. This results in a persistent allocation from the mempool. An attacker who can repeatedly trigger such failures could deplete memory resources, potentially degrading system performance or forcing a reboot. The abuse does not grant code execution; it is a gradual resource exhaustion attack.
Affected Systems
All current Linux kernel releases are potentially impacted until the patch that resolves the mempool leak is applied. The affected product is the Linux kernel; affected versions are unspecified, so all versions before the fix should be considered vulnerable.
Risk and Exploitability
The EPSS score indicates that the probability of exploitation is below 1%, and the vulnerability is not recorded in the CISA KEV catalog, implying no known active exploitation. Nonetheless, the impact of a successful leak can grow over time. The patch fixes the root cause by calling sd_uninit_command() on error and clearing the RQF_SPECIAL_PAYLOAD flag, eliminating the leak. Until the system is patched, the risk remains low to moderate due to the likely local, privileged nature of the triggering SCSI commands and the need for repeated failures to achieve significant impact.
OpenCVE Enrichment