Impact
The equilibrium pinctrl driver in the Linux kernel contains a code path that calls gpiochip_disable_irq during interrupt masking functions when the driver loads. Each call generates a warning trace in the kernel log, resulting in repeated warning messages for every GPIO device. The description does not indicate any loss of confidentiality, integrity, or availability; the effect is limited to noisy log output. The lack of explicit mention of escalation or data exposure means it is inferred that the vulnerability does not provide an attack surface for privilege escalation or information disclosure.
Affected Systems
All Linux kernel installations that contain the unmodified equilibrium pinctrl driver are affected. The driver is present in the generic Linux kernel (belonging to the Linux:Linux vendor). The CPE entries list kernel releases up to the 7.0 release candidates, and the kernel version 6.12.59+ noted in the example logs is indicative of a vulnerable build. Any build that incorporates the upstream equilibrium driver without the patch will display the warning trace during boot or module load.
Risk and Exploitability
The CVSS score of 5.5 classifies the issue as medium severity, while the EPSS score is below 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting a low operational risk. The likely attack vector is local system access during boot or driver load, which is consistent with the nature of a driver-level issue that only affects kernel log output. No direct exploitation path is described in the CVE data, and the impact remains confined to benign log noise.
OpenCVE Enrichment
Debian DSA