Impact
The vulnerability involves a NULL pointer dereference in the Stratix10 RSU firmware driver during the probe phase when a timeout occurs while an SMC call is still pending. This occurs because the driver frees a channel and clears a pointer that is later dereferenced by a kernel thread, causing a kernel crash. The flaw can lead to a denial of service if an attacker can trigger the probe sequence.
Affected Systems
All versions of the Linux kernel that include the Stratix10 RSU firmware driver before the commit that fixes the NULL dereference are affected. The flaw applies to the Linux vendor kernel and any distribution kernel that has not yet incorporated the patch. No specific distribution or kernel version list is provided in the advisory, so any Linux system that includes the Stratix10 RSU driver before the update is potentially vulnerable.
Risk and Exploitability
The CVSS score and EPSS are not disclosed in the available data, and the vulnerability is not listed in CISA’s KEV catalog. The bug can lead to a kernel crash, which may be leveraged for denial of service if an attacker can initiate the probe. The attack vector is inferred to be local, requiring access to the RSU hardware or the ability to load the driver. No publicly known exploits are documented.
OpenCVE Enrichment