Impact
The Linux kernel contains a flaw where LRU size accounting is mistakenly copied from a child memory cgroup to its parent during reparenting, leaving phantom counters on the child. These stale counters cause shrinker loops to repeatedly scan empty LRU lists, consuming CPU and memory resources. The result can be excessive CPU usage and memory pressure that may lead to system instability or crashes, effectively providing a denial‑of‑service condition.
Affected Systems
All Linux kernels that have not yet incorporated the patch moving LRU accounting from the child to the parent are affected. The CVE does not specify a distribution or release series, so any system running a kernel older than the commit that introduced the fix could be vulnerable. No other vendors or products are impacted.
Risk and Exploitability
The vulnerability is confined to kernel memory‑cgroup handling and requires manipulating kernel cgroup state, which typically necessitates privileged access. The EPSS score of less than 1 % and the absence from CISA’s KEV catalog imply a low likelihood of exploitation. Based on the description, it is inferred that an attacker would need to run privileged code or otherwise influence cgroup lifecycle events to trigger the flaw. When the defect is exercised, the resulting resource exhaustion can degrade system performance or cause a crash for all processes, representing a high impact for affected hosts.
OpenCVE Enrichment