Impact
The Linux kernel contains a use‑after‑free bug that occurs when a large page table (PMD) is collapsed while another thread holds a stale pointer to the page‑table page. The bug allows a write to freed memory, corrupting kernel data structures and potentially enabling arbitrary code execution in kernel mode.
Affected Systems
All Linux kernel builds that implement CPA page collapse without the fix, including those compiled with KASAN support, are vulnerable. No specific version range is listed, so any kernel prior to the commit that serializes the collapse operation is at risk.
Risk and Exploitability
Although the EPSS score is below 1% and the vulnerability is not in CISA’s KEV catalog, the use‑after‑free can provide a powerful local privilege escalation path. Exploitation requires concurrent module load and unload on a multi‑CPU system and may be easier on KASAN builds, but the lack of a public exploit suggests that the risk remains modest until the patch is deployed.
OpenCVE Enrichment