Impact
A use‑after‑free can occur in the Linux kernel when domain workers in the resctrl filesystem read event counters while the domain is being removed during CPU hotplug. The workers acquire a read lock, then the architecture releases a write lock and frees the domain, causing the worker’s container_of() dereference to free memory. This kernel‑space memory corruption could allow an attacker to corrupt data or execute arbitrary code, potentially leading to privilege escalation.
Affected Systems
Linux kernel, all configurations that enable the resctrl filesystem and CPU hotplug, regardless of distribution. The vulnerability affects any kernel that has not yet integrated the fix posted to the stable kernel tree via the git URLs provided. No specific version numbers are listed, so any in‑flight (unstable) kernel or kernels built from source that omit the update are susceptible.
Risk and Exploitability
The CVSS score is not supplied, but the use‑after‑free in privileged kernel code is a high‑severity flaw. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. However, given the kernel context, a local attacker with sufficient privileges to manipulate CPU hotplug or resctrl domains could potentially trigger the flaw, leading to a kernel crash or privilege escalation. The likely attack vector is local with privileged access, requiring the attacker to initiate domain removal or CPU unplug events. Overall, the risk remains significant as the flaw provides a kernel exploitation surface.
OpenCVE Enrichment