Impact
The fault occurs in the Linux kernel’s iomap subsystem, where a folio batch is not released when certain iomap callback functions fail. The batch holds references to memory pages; if left unreleased, successive failures can exhaust available memory, leading to system instability or denial of service. The vulnerability is confined to internal kernel operations and does not involve external input or user privileges directly; its primary impact is a resource leak that could degrade kernel performance and availability.
Affected Systems
This weakness affects Linux operating system kernels. No specific vendors or product versions are listed, so all distributions that ship the affected kernel code before the applied patch are potentially impacted.
Risk and Exploitability
The EPSS score is quoted as less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector would require triggering the failing iomap callback path, such as through XFS filesystem error conditions. Because the bug is limited to an internal kernel operation, successful exploitation most likely necessitates local or privileged access and would manifest as memory exhaustion rather than remote code execution. The overall risk, given its low EPSS and lack of active exploits, is considered low but should be mitigated before any remediation plans are finalized.
OpenCVE Enrichment