Impact
The vulnerability is caused by failing to free a buffer_head returned by ext4_bread() when orphan block validation fails. The unused buffer_head reference is leaked, which can lead to a gradual increase in memory usage and may ultimately cause kernel pressure or instability. No remote code execution or privilege escalation is achieved; the impact is limited to resource exhaustion.
Affected Systems
All Linux systems running the Linux kernel before the patch that addresses ext4_init_orphan_info. The exact kernel release is not enumerated in the data, but any distribution shipping a kernel that contains the legacy implementation of ext4_init_orphan_info is affected. The vulnerability is vendor-agnostic within Linux.
Risk and Exploitability
The EPSS score of < 1% indicates that exploitation is highly unlikely. The vulnerability is not documented in CISA’s KEV catalog, and no public exploit is known. The CVSS score of 5.5 indicates a medium severity. Given the nature of the flaw—memory leaking rather than direct compromise—the risk to confidentiality, integrity, and availability is considered low. Attackers would need uninterrupted access to the system to notice the memory leak, making the attack vector unfeasible over typical attack windows.
OpenCVE Enrichment
Debian DLA
Debian DSA