Impact
When a Digi AccelePort USB device performs an out‑of‑band write and the drive receives a persistent OOB write URB failure—such as during a physical disconnect—the kernel driver enters an infinite loop with interrupts disabled. The result is a hard lockup of the entire system, preventing normal operation and providing a clear denial‑of‑service condition.
Affected Systems
The vulnerability affects any Linux kernel installation that includes the digi_acceleport serial driver. All distributions that ship the generic Linux kernel with this driver are potentially impacted; no specific kernel versions are listed, so the issue is assumed to exist until a patched kernel is deployed.
Risk and Exploitability
The CVSS score for this flaw is 5.5, indicating moderate severity, while the EPSS score is less than 1%, suggesting a low exploitation probability at the present time. The vulnerability is not in the CISA KEV catalog. Exploitation would likely require a local attacker with physical access to a USB port capable of triggering an OOB write during a disconnect or close race condition. If achieved, the attacker can bring the system to a hard lockup state, effectively denying service.
OpenCVE Enrichment
Debian DLA