Impact
The bug was introduced when rebinding a static DAX device from the device_dax path to the fsdev_dax path. Because the vmemmap_shift field was not cleared, a stale value persisted on a shared page map, causing the kernel to build an incorrect virtual memory map for order‑0 folios. This incorrect map can lead to memory corruption or kernel exceptions during DAX operations.
Affected Systems
The vulnerability resides in the Linux kernel and affects any kernel that contains the faulty rebinding logic. As no specific version range is listed, all kernel releases prior to the patch that introduced the proper zeroing of vmemmap_shift are potentially impacted.
Risk and Exploitability
The EPSS score is lower than 1%, indicating a very low probability of exploitation in the field. The vulnerability is not yet listed in the CISA KEV catalog, so it is not a known exploit. Because the flaw involves internal kernel state the attack vector is likely local and requires triggering the rebind of a static DAX device, which would typically demand privileged access. Despite the low exploitation likelihood, an unpatched kernel could suffer severe instability or data loss if the condition were triggered.
OpenCVE Enrichment