Impact
The flaw in the Linux kernel’s liveupdate subsystem stems from incomplete state tracking when a firmware load block (FLB) retrieval fails. The system does not record a failed attempt, so a subsequent retrieval is retried without knowledge that the FLB instance is already in an altered or freed state. This can cause the kernel to invoke the retrieve callback on an invalid or already restored data structure, potentially leading to a kernel panic or other undefined behavior that disables the host. The weakness is a classic example of improper handling of function return values and a use‑after‑free scenario.
Affected Systems
Linux kernel installations are impacted. The vulnerability is present in all kernel releases prior to the commit that introduced the retrieval status tracking, identified by the references in the advisory. Specific version numbers are not listed, so any kernel older than the patched release should be considered vulnerable.
Risk and Exploitability
The exploitability of this defect is low, as indicated by an EPSS score of less than 1% and the absence from the CISA KEV catalog. The required conditions for successful exploitation include the ability to trigger a liveupdate retrieval operation, which typically demands elevated privileges or an existing kernel code execution vector. Once triggered, the bug can force a kernel crash, resulting in a denial of service that requires a system reboot.
OpenCVE Enrichment