Impact
The vulnerability in the Linux kernel’s ext4 file system allows a race condition between write_begin and write_end handlers during inline data writes. A concurrent operation such as ext4_page_mkwrite can convert inline data to an extent, causing the write_end logic to miss state checks and dereference a NULL pointer or trigger a BUG_ON, resulting in a kernel panic or data loss. The race can be leveraged by an attacker with local write access to trigger a crash or cause denial of service.
Affected Systems
The flaw exists in all Linux kernel versions that implement the ext4 file system and use inline data optimization. The affected products are categorized generically as Linux:Linux, covering every distribution that distributes the upstream kernel with ext4 support. No specific version range is provided, so any current or past kernel that has this inline data handling logic is impacted unless already patched.
Risk and Exploitability
The CVSS base score is not explicitly given, but the EPSS score is less than 1%, indicating low exploit probability in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The technical description indicates that exploitation requires a race condition and concurrent access to a file system with inline data, so it is likely a local denial of service scenario. The potential for a kernel panic makes the risk significant for systems that run unpatched kernels and expose users with write access to ext4 files.
OpenCVE Enrichment