Impact
This vulnerability occurs in the Linux kernel’s llbitmap subsystem. During the creation of a bitmap, the code publishes a pointer to mddev->bitmap before successfully reading the bitmap superblock. If reading fails, the cleanup path drops the bitmap mutex, frees the llbitmap object, and leaves the mddev->bitmap pointer dangling. Readers that rely on this pointer, such as /proc/mdstat, may then observe a stale pointer while holding the mutex, leading to a use‑after‑free. This flaw can potentially expose memory contents or crash the system, resulting in a denial‑of‑service or, if the attacker controls the memory region, arbitrary code execution. The weakness is a classic use‑after‑free (CWE‑416).
Affected Systems
Affected systems are any Linux kernels that include the llbitmap code before the commit that introduced the fix. The issue is present across all mainstream Linux distributions that ship the kernel versions containing the unpatched llbitmap module. No specific vendor or product name beyond "Linux kernel" is listed in the vendor/product data.
Risk and Exploitability
The exploit probability is very low with an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog, suggesting limited exploitation activity. However, the commit that fixed the issue is available on the official kernel Git tree, and the CVSS score is not listed, but the use‑after‑free indicates a notable severity. Attackers would need kernel or root access and a failure condition within llbitmap_read_sb(). The risk is primarily a local denial‑of‑service, though a crafted environment could lead to memory corruption or code execution if memory is overwritten after the use‑after‑free. The likely attack vector is local and requires kernel privileges.
OpenCVE Enrichment