Impact
In the Linux kernel, the NXP NFC NCI driver contained a logic error that prevented certain GPIOs from sleeping, causing a WARN_ON and disabling operation of GPIOs connected to I2C expanders. The patch removes the warning and allows normal operation. No evidence of direct integrity, confidentiality, or availability compromise is documented; the issue is classified under CWE-372 and the ancillary NVD-CWE-noinfo, indicating potential defensive instrumentation problems rather than a clear attack vector.
Affected Systems
Any system running a Linux kernel that includes the nxp-nci NFC driver is affected. The problem is present in kernel versions prior to the commit that introduced the fix; the exact version ranges are not specified in the advisory.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium severity range. The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. No exploit code or proof‑of‑concept has been reported, and the described issue affects only internal driver behavior.
OpenCVE Enrichment
Debian DLA
Debian DSA