Impact
During driver detach in the Linux kernel, an incorrect iterator causes the same hash algorithm to be unregistered multiple times, leading to a kernel panic. The flaw enables a local attacker with sufficient privileges to force the kernel to crash, resulting in a complete loss of system availability.
Affected Systems
All Linux kernel versions running the vulnerable driver before the commits that fixed the issue are affected. No specific release numbers are listed, but any kernel containing the unpatched driver code is at risk. The vendor is the Linux kernel project.
Risk and Exploitability
Exploitability is high for a local privileged user with the ability to unload or reload the kernel module. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the severity of a kernel panic implies a critical impact. The attack vector is inferred to be local, requiring privileged interaction to trigger the vulnerable module detach.
OpenCVE Enrichment