Impact
A privileged user writing to bridge port sysfs attributes triggers the brport_store function to acquire a bridge lock that can sleep. When executed in atomic context, the resulting sleep‑triggering call dev_set_promiscuity causes a kernel oops. The crash removes kernel availability, providing a denial of service. The weakness is an improper use of a blocking synchronization primitive.
Affected Systems
Any Linux kernel build that does not incorporate the commit referenced in the advisory is affected. This includes all distributions shipping the unpatched mainline kernel, as well as custom kernels that lack the fix. The advisory does not list specific build numbers, so any kernel before the fix is at risk.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires write access to bridge sysfs entries, limiting it to a local privileged user such as root or a user with CAP_SYS_ADMIN. The typical attack vector is a local privileged user altering a bridge sysfs attribute, leading to a kernel crash. No publicly available exploit is documented, so the overall risk remains low under normal circumstances.
OpenCVE Enrichment
Ubuntu USN