Impact
A kernel array overflow can be triggered in the Intel uncore PMU discovery routine when a die is offline but still parsed, leading to a kernel warning or crash that renders the host unavailable.
Affected Systems
Any Linux kernel build before the commit that fixed the Intel uncore PMU discovery bug is affected. No specific kernel version is given, so older kernels lacking the fix are vulnerable.
Risk and Exploitability
Exploitation requires the system to boot with NUMA disabled and fewer CPUs enabled than the number of CPUs in die 0. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The CVSS score of 7.0 reflects a high-severity buffer overflow, and while the attack conditions are boot-time configurations, the defect could cause a denial of service if attacker-controlled boot parameters are used.
OpenCVE Enrichment