Impact
The Linux kernel contains a flaw in the ext4 filesystem's directory read routine. Under certain conditions a corrupted directory entry can cause the kernel to perform an out‑of‑bounds access during ext4_readdir(). The resulting KASAN trace shows a use‑after‑free of the directory buffer, potentially causing kernel memory corruption.
Affected Systems
All Linux distributions that ship the current ext4 implementation are potentially affected until the kernel patch described in the commit references is applied. No specific version list is provided, so any kernel prior to the fix is considered vulnerable. The issue exists in the core ext4 filesystem module and applies to ext4 mounts regardless of encryption or other features.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low but non‑zero exploitation probability as of the latest update. The flaw requires an attacker to craft a corrupted directory and read it locally; thus the primary attack vector is local. The vulnerability could be leveraged by a privileged user or an attacker who can influence directory contents, leading to kernel memory corruption. No publicly available exploit is referenced, but the low EPSS and lack of KEV presence suggest that immediate patching is prudent to pre‑empt future exploitation.
OpenCVE Enrichment