Impact
In the Linux kernel, deactivating a GPIO aggregator that was created via configfs can leave a dynamically allocated software node undeleted. This causes a leak of kernel memory resources that can accumulate over time. The weakness is a resource handling issue (CWE‑772). The vulnerability does not provide direct code execution or data exfiltration. Based on the description, repeated deactivation could lead to memory exhaustion, which might impact availability.
Affected Systems
Affected systems include any Linux kernel builds that include GPIO aggregator support through configfs. These are all Linux kernel versions before the fix introduced in commit 3e657619cf7258cb53b1beaf0d02998297695cde. The vendor is Linux, the product is the Linux kernel. Any distribution or custom kernel that incorporates the unpatched code is potentially impacted.
Risk and Exploitability
The EPSS score of less than 1 percent indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack vector requires the ability to deactivate a running GPIO aggregator, which could happen during routine operation or by privileged software. Since it is a memory leak, the threat to confidentiality and integrity is minimal. Based on the description, persistent activity could lead to kernel memory exhaustion, which might impact availability.
OpenCVE Enrichment
Ubuntu USN