Impact
A race condition in the Linux kernel’s OCFS2 module couples heartbeat callbacks with the teardown of the o2net transport. When a node‑down event triggers a heartbeat while the transport is being stopped, the code attempts to queue work onto a workqueue that has already been destroyed. The resulting use‑after‑free is detected by KASAN as a slab‑use‑after‑free in __queue_work, which corrupts kernel memory. If an attacker can control the timing of the heartbeat and the teardown on a local system, the memory corruption could be leveraged to crash the system or, by manipulating kernel memory, to gain higher privileges.
Affected Systems
The vulnerability exists in the Linux kernel’s OCFS2 file‑system code. It applies to all distributions that ship the unmodified kernel with OCFS2 support; no specific version information is provided, so any kernel revision prior to the application of the “hardening heartbeat teardown races” patch may be affected.
Risk and Exploitability
The CVSS score is not disclosed, but the EPSS indicates an exploitation likelihood of less than 1 %. The bug is not listed in the CISA KEV catalog, suggesting no widely reported exploitation yet. Because the race requires a local node with OCFS2 configured, the attack vector is local, and a user with sufficient access to control configfs or trigger heartbeats could exploit the race. Timing precision is required, but the presence of a use‑after‑free and the lack of an access control check make the risk significant for environments running OCFS2 clusters.
OpenCVE Enrichment
Debian DLA
Debian DSA