Impact
This bug allows two separate userspace tasks to exchange a memalloc_noio token during kernel suspend/resume operations. By writing to the suspend sysfs entries concurrently, a task can enter the PF_MEMALLOC_NOIO state, return to userspace while still holding the token, and later another task can restore that same token, effectively hijacking the allocation guard. The result is that memory is allocated or de‑allocated under incorrect assumptions about the device’s state, potentially leading to data corruption or elevated privileges for the attacker. The weak point is a classic race condition, as the token’s lifetime is incorrectly tied to the device instead of the operation that set it.
Affected Systems
The vulnerability exists in all Linux kernel builds that contain the original memalloc_noio handling code before the commits that introduced the quick‑fix described in the advisory links. Versions of the kernel that have not incorporated the changes identified by the git commits 28fdea874f68..., 72ebfdf507e..., a58923756b0..., and bace2010dd7... are affected. In practice, every stable or mainline kernel released before the patch set is at risk until the kernel is updated to include the fixes.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a low probability of public exploitation, and the vulnerability is not listed in CISA’s KEV catalog. No CVSS score is available in the published data, so the exact severity is unknown. The attack appears to require local privilege and concurrency between tasks that write to the MD suspend sysfs paths. While the described race could cause system instability or subtle corruption, it presents a potential for privilege escalation if the attacker can force the kernel to allocate memory with an incorrect flag. Given the low EPSS and lack of a public exploit, the risk is moderate but non‑negligible, and the issue should be remediated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA