Impact
A fault in the Linux kernel media driver for the OV8856 camera sensor over I2C causes the control handler to remain allocated when control initialization fails, resulting in a memory leak. The unchecked allocation can lead to exhaustion of kernel memory resources and potentially render the device or the entire system unavailable.
Affected Systems
Any Linux kernel installation that includes the media subsystem driver for the OV8856 sensor is affected. The vulnerability is present in versions of the kernel that have not yet incorporated the fix for the control, regardless of distribution vendor.
Risk and Exploitability
The CVSS score of 5.5 classifies the issue as medium severity, while the EPSS score of less than 1% indicates a very low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation would require local kernel access to trigger repeated driver initialization failures, and the likely attack vector is local; this inference is drawn because the vulnerability involves a memory leak during driver initialization that a local attacker could potentially exploit.
OpenCVE Enrichment
Ubuntu USN