Impact
A concurrent user fault can call show_pte() without acquiring the mmap write lock when CONFIG_DEBUG_USER is enabled and user_debug=31 is set. If another thread in the same process calls munmap() at the same time, the page table structures may be freed while show_pte() is still reading them, yielding a use‑after‑free. On ARM systems compiled with CONFIG_ARM_LPAE, this race can trigger a kernel panic as the PMD page table is released during the fault handling. The flaw does not provide direct code execution, but it can destabilize the operating system and may allow a local attacker to repeatedly crash the machine.
Affected Systems
The issue exists in all Linux kernel releases that contain the affected mm/show_pte code path prior to the commit that adds mmap_write_lock. It is relevant to every vendor and distribution that uses the mainstream Linux kernel with CONFIG_DEBUG_USER enabled. The specific affected kernel versions are not enumerated in the advisory, so any kernel built from source that has not yet applied the patch is potentially vulnerable.
Risk and Exploitability
The vulnerability has an EPSS score of less than 1 % and is not listed as a CISA Known Exploited Vulnerability, indicating a relatively low public exploitation probability. Nonetheless, the impact of a kernel panic is high, as it results in a denial of service for the local user or any process running on the machine. Because the flaw requires a race condition between user‑fault handling and munmap() within the same process, a local attacker can trigger the failure by orchestrating such a timing window, for example by launching multiple threads that fault and unmap concurrently. Given the lack of a publicly known exploit and the low EPSS, the overall threat is moderate to high, but it is still urgent to apply the kernel patch to eliminate the race condition.
OpenCVE Enrichment
Debian DLA
Debian DSA