Impact
In the Linux kernel’s block‑layer memory bitmap (md/md‑llbitmap) a timer that cleans dirty chunks may be rearmed after it has already been deleted during teardown. The daemon work can still be queued or still be running, so the timer can be armed again with a pointer to memory that has already been freed. This use‑after‑free can corrupt kernel memory, potentially causing a crash or providing an attacker with code execution in kernel mode.
Affected Systems
The flaw applies to the Linux kernel across all distributions that include the md/md‑llbitmap subsystem; vendor or version restrictions were not supplied, so every Linux kernel installation that uses this subsystem is potentially vulnerable until the patch is deployed.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the weakness is not listed in the CISA KEV catalog, suggesting that active exploitation is very low at the time of this analysis. However, because the flaw occurs in privileged kernel code, a local attacker with the capability to trigger the teardown path or manipulate block devices can exploit the use‑after‑free to crash the kernel or elevate privileges. The attack vector is inferred to be local, requiring legitimate kernel access or the creation of a block device. Given the severity of kernel memory corruption, the risk remains high until the fix is applied.
OpenCVE Enrichment