Impact
In the Intel i915 graphics driver, the pointer set_default_submission is left uninitialized when firmware binaries are missing. During system suspend, the driver dereferences this pointer, causing a NULL pointer dereference that brings the kernel down with an Oops. The exploitation results in a local kernel crash, forcing a system reboot or service interruption, and can be leveraged to disrupt availability if an attacker can trigger suspend on a target system.
Affected Systems
All builds of the Linux kernel that include the i915 driver and lack the required Intel GPU firmware binaries, before the commit that adds a null check. This applies to installations running kernel versions prior to the fix implemented in commit daa199abc3d3d1740c9e3a2c3e9216ae5b447cad, which was initially part of kernel 6.19‑rc4 at release.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attack requires local or privileged access to the target system to trigger a suspend operation, after which the NULL dereference crash occurs. With a CVSS score of 5.5, the vulnerability is assessed as medium severity. Although the likelihood of spontaneous exploitation is minimal, a determined attacker who can influence suspend actions could cause destructive denial of service by forcing frequent crashes.
OpenCVE Enrichment
Debian DLA
Debian DSA