Impact
A flaw in the Mediatek PCI implementation of the Linux kernel causes IRQ domains that are established during port initialization to remain allocated when an enable operation fails. The missing cleanup path results in a leak of kernel resource descriptors. Over time repeated failures could accumulate many unused IRQ domain objects, potentially depleting the pool of available IRQ resources and degrading system stability. The description does not confirm that this will immediately trigger a kernel panic or denial‑of‑service, only that a resource leak occurs.
Affected Systems
All Linux kernel installations that employ the unpatched Mediatek PCI driver are affected. The flaw exists in any kernel version that includes the legacy mtk_pcie_enable_port implementation, and it is not tied to a specific distribution or kernel release. Systems running a Mediatek PCI device that is managed by the affected driver before the patch are at risk.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. Exploitation would require triggering a port enable failure, which typically requires local or privileged access to modify device configuration or to influence the hardware state. No remote or user‑facing input is required by the provided description, so the attack surface appears limited to scenarios where the failure path can be exercised.
OpenCVE Enrichment
Debian DLA
Debian DSA