Impact
The vulnerability in the Linux kernel arises when the nvme-apple driver initializes a queue and immediately marks it as enabled without using a release memory ordering. This omission means that the earlier initialization may not be visible to other CPUs before the enabled flag is read in interrupt or request paths, giving rise to a race condition where an operation could proceed on an uninitialized queue. The result could be data corruption or kernel instability and is rooted in a concurrency bug involving improper acquire/release semantics.
Affected Systems
All Linux kernel builds that include the nvme-apple driver before the fix are affected. The flaw applies to the general Linux kernel and the Apple integration within it, covering all releases that contain the nvme-apple code prior to the commit that introduced acquire/release fences. No explicit version numbers are listed, so any kernel module built from the unpatched source is considered vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability does not appear in the CISA KEV catalog, indicating a low likelihood of exploitation. While the CVSS assessment is unspecified, the race condition could lead to unpredictable kernel behavior or data corruption. An attacker would need local kernel or privileged code execution to manipulate the nvme-apple queue state, making the risk moderate but unlikely to be actively targeted.
OpenCVE Enrichment
Debian DLA
Debian DSA