Impact
The kernel missing a check for a failed per‑CPU area allocation causes a null pointer dereference when the code offsets into the per‑CPU area. This results in an oops that can crash the operating system, providing a denial‑of‑service vector. The weakness is an unchecked null pointer dereference (CWE‑476).
Affected Systems
All versions of the Linux kernel that lack the patch addressing the crash when allocating per‑CPU memory during hot‑plug node addition are affected. The exact version range is not specified in the data; any kernel that includes the mm/mm_init code without the described fix is vulnerable.
Risk and Exploitability
The vulnerability is a null pointer dereference (CWE‑476). An attacker can trigger the defect by attempting to hot‑plug memory or otherwise force the kernel to allocate per‑CPU node statistics, which will fail and cause a crash. The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog, but the impact of a kernel crash provides a denial‑of‑service vector. The attack vector is likely local, but could be escalated via compromised kernel memory if an attacker can control hot‑plug operations. The CVSS score is not provided; however, the described denial of service and kernel crash denote high severity.
OpenCVE Enrichment
Debian DLA
Debian DSA