Impact
When an I/O error occurs while writing the Logical Volume Integrity Descriptor buffer, the kernel’s completion handler clears the buffer’s uptodate flag but retains valid in‑memory data. Subsequent attempts to mark the buffer dirty trigger a spurious WARN_ON_ONCE warning because the flag is reset. The kernel patch restores the uptodate flag before marking the buffer dirty, preventing the warning. There is no evidence that this flaw allows an attacker to alter data integrity, force a denial of service, or gain any other security advantage.
Affected Systems
All Linux kernel releases that contain the UDF (Universal Disk Format) filesystem and have not yet incorporated the patch that restores the uptodate flag for the LVID buffer. The vulnerability is identified in the kernel’s buffer management code and applies to the UDF filesystem component of the Linux kernel.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. The CVSS score is not disclosed but the lack of a clear attack vector and the trivial nature of the bug suggest that the overall risk to confidentiality, integrity, or availability remains negligible.
OpenCVE Enrichment
Debian DLA
Debian DSA