Impact
The likely impact, as inferred from the description, is that the underflow may cause a kernel crash or create a use‑after‑free that could be exploited, but the advisory does not confirm a successful code execution path. The vulnerability involves a reference count underflow and potential use‑after‑free in the Linux kernel's keyring handling. When restore_dm_crypt_keys_to_thread_keyring() obtains a reference to a user keyring and passes it to add_key_to_keyring() for many keys, the reference is dropped an extra time. If more than five keys are restored, this can result in a refcount underflow, triggering a warning or a kernel crash. A use‑after‑free of the keyring object could allow an attacker to execute arbitrary code or crash the system, compromising confidentiality, integrity, and availability.
Affected Systems
Affected systems are machines running the Linux kernel. No specific kernel versions are enumerated in the advisory, so all kernel releases that contain the old implementation are potentially vulnerable unless patched. The problem is present in the core kernel code that handles dm‑crypt key restoration.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is local privileged or an environment that can manipulate dm‑crypt keyring contents. The EPSS score is less than 1 %, indicating a very low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Without an official patch cited, the likelihood of a publicly available exploit remains low. The vulnerability would require the attacker to trigger dm‑crypt key restoration with multiple keys, which is probable only in environments that use disk encryption and have the ability to influence the keyring contents, implying a likely local privileged attack vector.
OpenCVE Enrichment