Impact
The vulnerability arises because the msb_init_disk function creates a per-card ordered workqueue but the msb_remove function never destroys it. Each time a card is inserted and removed, the workqueue and its kworker persist, leaking kernel memory. Over many cycles, this memory leak can consume all available kernel memory, potentially causing the system to become unresponsive or crash. The weakness is a classic resource exhaustion flaw.
Affected Systems
All Linux kernel configurations that include the memstick ms_block interface are affected. The issue applies to the Linux vendor across all released kernel versions that incorporate this driver code.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in CISA KEV, indicating a lower public exploitation footprint. The CVSS score is not provided, but an unmitigated resource leak can lead to a denial of service. The likely attack vector requires physical manipulation of a memstick device, making the risk moderate to high in environments where device insertion and removal happen frequently. Until a patch is applied, the vulnerability remains exploitable by local privileged code or automated scripts that repeatedly cycle device connections.
OpenCVE Enrichment