Impact
A NULL function pointer dereference in the 8250_mid driver can trigger a kernel oops on DNV, Ice Lake Xeon D, and Snowridge platforms. This flaw arises because setup and exit callbacks are set to NULL and are later dereferenced without checks, causing a crash and potential denial of service. The weakness is a standard NULL pointer dereference (CWE‑476).
Affected Systems
All Linux kernel implementations that include the 8250_mid driver on Denverton (DNV), Ice Lake Xeon D (ICX‑D/CDF), or Snowridge (SNR) hardware, prior to the inclusion of commit b1b4efea05a5.
Risk and Exploitability
The EPSS score is <1%, indicating a very low exploitation probability. The CVSS score of 5.5 indicates a moderate severity. The flaw is not yet catalogued in the CISA KEV list, and no public exploit is known. Based on the description, it is inferred that a successful exploit would require local or privileged access to the system, as the failure occurs in kernel space. In practice, the risk profile is moderate–low, focusing primarily on denial of service when the driver is exercised.
OpenCVE Enrichment
Debian DLA