Linux Kernel Cachefiles KASAN Slab-Out-Of-Bounds Vulnerability

Vulnerability

A slab-out-of-bounds vulnerability has been identified in the Linux kernel's cachefiles component. This issue arises in version 5.18.0-rc1-nfs-fscache-netfs and is related to how volume coherency data is handled when setting extended attributes. The vulnerability was detected by the Kernel Address Sanitizer (KASAN), which reported a memory access error caused by a task writing beyond the allocated buffer size. This improper handling of data can potentially be exploited to manipulate memory, leading to undefined behavior or memory corruption.

Impact

Exploitation of this vulnerability could result in a heap-based buffer overflow, allowing for memory corruption or arbitrary code execution.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.