Impact
The flaw occurs when fan data becomes zero between a validity check and a conversion to RPM, causing a divide‑by‑zero calculation that crashes the kernel. This triggers a kernel panic and results in a denial of service. It is a classic race condition (TIME‑OF‑CHECK/TIME‑OF‑USE) that can be abused by an attacker with sufficient access to trigger fan speed reads.
Affected Systems
The vulnerability affects the Linux kernel through the adt7470 hardware monitoring driver. No specific kernel versions are listed, so any kernel that includes the adt7470 module before the patch is impacted.
Risk and Exploitability
EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of exploitation is unknown. The attack requires local execution with privileges sufficient to access the hardware monitoring interface or to trigger a fan speed read. As the fault causes a kernel crash, the impact is a denial of service that may affect the entire system. The CVSS score is not provided, but the nature of the defect warrants cautious treatment.
OpenCVE Enrichment