Impact
A race exists in the Linux kernel where a hotplug or link‑loss event tears down the Multi‑Stream Transport topology while a probing function is concurrently invoked. The function checks under a lock, but the topology can be dismantled before the lock is acquired, leading to spurious kernel warnings and compositor crashes when DP MST monitors are attached or removed.
Affected Systems
Any Linux kernel that supports DisplayPort Multi‑Stream Transport is potentially affected. No specific kernel version is restricted, so older kernels lacking the fix and newer upstream kernels without the patch may both run at risk as long as DP MST support is enabled.
Risk and Exploitability
The EPSS score is <1 %, indicating a low likelihood that this race will be actively exploited. It is not listed in CISA’s Known Exploited Vulnerabilities catalog. The CVSS score of 5.5 reflects a moderate severity. As before, the vulnerability does not compromise confidentiality or integrity; its impact is limited to operational instability caused by kernel warnings and compositor crashes. Exploitability requires a hotplug or link‑loss event on a system with DP MST enabled and an active compositor.
OpenCVE Enrichment
Debian DLA