Impact
A missing channel array in a mailbox controller can lead to an OOPS when the kernel attempts to dereference a null pointer. This failure results in a kernel crash, causing system downtime. The vulnerability does not directly expose data, but it can be used by an attacker to destabilize the system and create a denial of service condition.
Affected Systems
All Linux kernel releases that contain the mailbox driver without the sanity check are potentially affected. The exact kernel versions are not listed in the data, but the issue is mitigated in the latest branches that include the commit adding the check.
Risk and Exploitability
No CVSS score is provided and the EPSS value is unavailable. The vulnerability is not listed in the CISA KEV catalog. Given that a kernel crash can lead to a denial of service and the attack requires code execution within the kernel, the risk remains high until a patch is applied.
OpenCVE Enrichment