Impact
The Linux kernel virtio_pmem driver contains a use‑after‑free flaw, identified as CWE‑416. When a virtio_pmem request is queued, the driver keeps a reference to the request token via the virtqueue. After the submitter frees the request, the virtqueue still holds a dangling reference, causing __wake_up_common() to operate on freed memory. The resulting slab‑use‑after‑free can corrupt kernel data structures and is likely to crash the kernel, potentially allowing a malicious actor to disrupt system availability.
Affected Systems
All Linux kernel builds that incorporate the unpatched virtio_pmem implementation are at risk. No specific affected version range is supplied, but the issue was present at least in the 6.19‑next branch at the time of disclosure. Servers, desktop distributions, or embedded devices running any kernel that includes the virtio_pmem driver before the reference‑counting patch are susceptible.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score is reported as less than 1 %, suggesting a very low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Attackers would need the ability to interact with a virtio_pmem device, which typically requires local access or privileged execution. While the low EPSS score reflects limited exploitation risk, the potential for a kernel crash warrants urgent remediation.
OpenCVE Enrichment