Impact
In the Linux kernel, the function __fsdev_dax_direct_access calculates a kernel virtual address for a DAX device by adding a linear offset to a base address instead of translating the physical address directly. For devices that provide multiple non‑contiguous physical ranges, this arithmetic can cross a gap and produce an invalid kernel virtual address. The resulting address misresolution could cause corrupt kernel memory accesses or system crashes. The weakness corresponds to CWE‑409, which involves race conditions or time‑of‑check to time‑of‑use errors that can be triggered when a system computes an address based on outdated or incorrect information.
Affected Systems
All Linux kernel builds that include the dax/fsdev subsystem. Any distribution or custom kernel that has not incorporated commit 7b642bd3… and its patch is affected. No explicit version list is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% reflects a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation appears to require direct interaction with a DAX device that has multiple physical ranges, implying a privileged or local scenario. No evidence of remote exploitation exists.
OpenCVE Enrichment