Impact
The vulnerability is a kernel‑level race condition affecting the exfat filesystem. When a file is mapped for shared writable access, the kernel expands the valid size of the mapping during a write or a fault and zeroes the gap in the page cache. A concurrent store through the mapping can race with this zeroing operation and be overwritten, potentially causing data loss or corruption. The flaw does not directly grant code execution but results in integrity violations of user files accessed via such mappings.
Affected Systems
All Linux kernels that include the exfat filesystem module are affected, regardless of distribution. The issue is present in any kernel build that uses the standard exfat driver, as identified by the generic Linux kernel CPE string.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score is under 1 %, indicating a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need local user access to a system with exfat support and the ability to create a shared writable mapping. Given the low exploitation probability and absence of a known public exploit, the overall risk remains moderate but not negligible.
OpenCVE Enrichment