Impact
The Linux kernel contains a bug in the SCSI disk driver where failure to create a large memory pool during device probing can cause the kernel to unregister and free a device that is still registered. This leads to a kfree of a live device reference and leaves a broken sysfs entry, potentially triggering a kernel panic or memory corruption. The effect is a denial of service and, because the fault occurs in kernel space, it could allow a local attacker to gain elevated privileges or execute arbitrary code if they can force the failure path.
Affected Systems
The flaw resides in the Linux kernel’s SCSI subsystem and affects any Linux system running a kernel version that includes the vulnerable sd_probe() implementation. No version range is specified, so any distribution that has not yet applied the fix is potentially impacted.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high impact, but its EPSS score of less than 1% indicates that exploitation has not yet been observed in the wild. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is local, requiring an attacker to manipulate SCSI device creation or trigger large pool allocation failures, which may be feasible for privileged or unprivileged users on systems with exposed SCSI disks.
OpenCVE Enrichment