Impact
A race condition in the Linux kernel’s resctrl subsystem allows a use‑after‑free bug when the reference counter for an rdtgroup structure is decremented outside the mutex protecting the object. If two free paths execute concurrently, the structure may be freed and then accessed again, which can lead to arbitrary kernel code execution or denial of service. This flaw is a classic memory corruption vulnerability that is exploitable once the attacker can trigger the concurrent release and teardown operations.
Affected Systems
The vulnerability affects any Linux system running a kernel that implements the resctrl feature without the protective change. No specific kernel versions are listed, so all releases that contain the unpatched resctrl code are potentially impacted. The issue is present in the core kernel, not an add‑on module.
Risk and Exploitability
The EPSS score is less than 1 % and the flaw is not currently listed in the CISA KEV catalog, indicating low to moderate evidence of active exploitation. The CVSS score is not provided, but use‑after‑free bugs usually carry a high severity rating. Attackers would need the ability to perform concurrent resctrl operations—typically via privileged userspace processes or scripts that write to resctrl directories while the filesystem is being unmounted or cleaned up. Based on the description, the likely attack vector is local privileged access rather than remote exploitation.
OpenCVE Enrichment