Impact
The Linux kernel function dax_holder_notify_failure() reads the dax_dev->holder_ops pointer twice without proper memory ordering. A concurrent fs_put_dax() can clear this pointer between the NULL check and the dereference, leading to an indirect null pointer dereference that crashes the kernel. This defect falls under the CWE-476 (Null Pointer Dereference) and CWE-362 (Concurrent Modification of Data with No Synchronization). The resulting kernel crash can cause a service interruption or require a system reboot, but it does not provide remote code execution or direct privilege escalation.
Affected Systems
All versions of the Linux kernel that include the DAX (Direct Access) subsystem and have not been updated to a version where dax_holder_notify_failure() stores holder_ops once with READ_ONCE(). The impact covers all Linux distributions that ship the affected kernel code.
Risk and Exploitability
The EPSS score for this vulnerability is less than 1% and it is not listed in the CISA KEV catalog, indicating a very low probability of exploitation under current threat intelligence. The CVSS score is not specified, but the risk is assessed as low to moderate due to the necessity of a local race condition and the lack of a known efficient attack vector. Nevertheless, the crash can jeopardize availability in mission‑critical environments, making timely remediation advisable.
OpenCVE Enrichment
Debian DLA
Debian DSA