Impact
The Linux kernel change in the dax/fsdev driver leaves stale function pointer and owner references on the shared page map after a static device is unbound. When the device is later rebound or the module unloaded, a memory failure triggers the stale handler, which may reference freed memory. This use‑after‑free can allow arbitrary code execution in kernel mode. The likely attack vector is a local action that unbinds and rebinds a static DAX device or unloads the fsdev_dax module, actions that typically require root privileges or the ability to manipulate device bindings.
Affected Systems
All Linux kernel builds that include the dax/fsdev driver are potentially impacted. The vulnerability exists until the kernel patch that registers a devm action to clear pgmap->ops and pgmap->owner on unbind is applied.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low historical exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. The likely exploitation scenario involves local privilege escalation, inferred from the need to unbind and rebind a static DAX device or unload the fsdev_dax module, actions that typically require root access. Because the flaw relies on device‑specific operations and memory failure conditions, a competent attacker could leverage it in a privileged environment. The risk is therefore considered moderate to high for affected systems that expose DAX devices.
OpenCVE Enrichment