Impact
The vulnerability is a use‑after‑free in the Linux kernel’s kmod duplicate request handling. The bug occurs when a kmod_dup_req instance is freed before all references are released because the code incorrectly uses RCU. An attacker could trigger this flaw to corrupt kernel memory, possibly gaining elevated privileges or crashing the system. The weakness is a classic use‑after‑free, which can lead to arbitrary code execution at kernel level. The explicit attack vector is not stated; based on the description, it is inferred that local exploitation via a malicious module load request on a system running the vulnerable kernel is possible. The description does not specify how an attacker could trigger the flaw, so the attack vector is inferred rather than confirmed.
Affected Systems
All Linux kernel builds that contain the kmod/dups implementation before the advertised commit are potentially affected. The CVE references multiple kernel git patches; regardless of the exact kernel version, any system running a kernel that has not been updated to include the reference‑counting fix is at risk. Specific kernel versions are not enumerated in the data, so it is inferred that any build preceding the commit that adds reference counting remains vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is less than 1%, showing low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the failure occurs in kernel space, so local or physical attackers can potentially exploit the flaw. An exploit would require triggering the freed object, which may involve submitting a malformed module load request or similar. Since the issue is not tied to user‑space privileges, the risk remains high for any system where kernel developers rely on the duplicated module logic. The CVE does not provide a known exploit; the low EPSS indicates that exploitation is unlikely at present. The risk assessment infers that a local or physical attacker could potentially exploit the flaw, but the exact feasibility remains uncertain.
OpenCVE Enrichment
Debian DLA
Debian DSA