Impact
In the Linux kernel, a flaw occurs when hugetlbfs is mounted with size or min_size options. The mount routine allocates a hugepage subpool, but if the creation of the root dentry fails, the failure path frees the subpool with kfree(), bypassing the standard hugepage_put_subpool() cleanup. The result is that the allocated subpool's min_size reservations remain charged, potentially exhausting the system's hugepage pool. This is an uncontrolled resource consumption issue described by CWE‑400. Based on the description, it is inferred that the vulnerability is triggered only when a filesystem is mounted, requiring sufficient privileges to perform the mount operation. The attack vector is thus local with privileged access.
Affected Systems
The vulnerability affects any Linux kernel that implements hugetlbfs with the described free path. No specific kernel release numbers are listed, so all current and historical kernels before the patch may be impacted. Users who mount hugetlbfs with size or min_size options and encounter a mount failure are at risk. Workloads that rely on hugetlbfs might become blocked when the hugepage pool is depleted. The absence of explicit version coverage means the impact is inferred to apply to all kernel versions containing the affected code path. The CVE description does not list affected product variants; thus the inference covers all Linux kernels exposing hugetlbfs.
Risk and Exploitability
The risk can be rated high because a local attacker with privileges to mount filesystems could trigger the failure path and deplete hugepages, leading to denial of service for the system. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires privileged access and therefore is most relevant to administrators controlling privileged accounts. The patch introduces a proper call to hugepage_put_subpool() on failure, eliminating the leak. Based on the EPSS score and lack of known exploitation records, the likelihood of exploitation remains low, but the impact remains severe if successful. The analysis infers that remote exploitation is unlikely due to the need for privileged mount access. The CVE data does not provide exploit code, so this conclusion is based on inference.
OpenCVE Enrichment
Debian DLA
Debian DSA