Impact
During driver detach in the Linux kernel, an incorrect iterator causes the same hash algorithm to be unregistered twice, leading to a kernel panic. This flaw permits a local attacker with sufficient privileges to force the kernel to crash, resulting in complete loss of system availability.
Affected Systems
All Linux kernel versions that include the vulnerable inside-secure/eip93 driver code before the commits that fixed the bug are affected. No specific release numbers are listed, but any kernel containing the original unpatched driver implementation is at risk. The vendor is the Linux kernel project.
Risk and Exploitability
Exploitability requires a local privileged user able to unload or reload the kernel module. The EPSS score is less than 1%, indicating a low probability that the vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. The severity of an immediate kernel panic is critical, and the likely attack vector is local, requiring privileged interaction with the kernel module.
OpenCVE Enrichment