Impact
Based on the description, the Linux kernel module loader fails to validate the ELF section index referenced by a symbol. When a module contains an out‑of‑bounds st_shndx value, the loader accesses memory outside the allocated array, resulting in a page‑fault and a kernel panic that stops the system.
Affected Systems
All Linux kernel releases are affected because the vulnerability resides in generic loader code shared across distributions; no specific vendor or product version is listed.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate‑severity denial of service. The EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog, suggesting no widespread active exploitation. Based on the description, it is inferred that the attack vector requires the attacker to load a malicious or corrupted kernel module, which generally implies local privileged access or an environment that permits untrusted module loading.
OpenCVE Enrichment
Debian DLA
Debian DSA