Impact
In the Linux kernel a memory‑fault handling path can acquire the mmap lock twice when a retry is attempted after failing to acquire the arena lock, causing a deadlock. The deadlock may halt kernel activity and result in a denial of service. The flaw occurs during kernel fault handling; it is therefore a low‑level race condition that can be triggered by operations that cause address faults in a bpf program. Based on the description, the likely attack vector is an attacker with the ability to run code in the kernel or to provoke fault conditions from user space, such as a malicious or misbehaving bpf program. The impact is confined to the affected kernel operating system. The vulnerability is cataloged under CWE‑847 (Improper Synchronization).
Affected Systems
Linux kernel products from the mainline Linux distribution are affected. No specific kernel versions are enumerated in the available data, so all releases that include the bpf subsystem are potentially impacted until a patch is applied.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. However, because the flaw leads to a kernel deadlock, it can cause a system‑wide denial of service if successfully triggered. The need for privileged code or ability to induce faults means an attacker would need significant access, but once attained the effect is severe.
OpenCVE Enrichment