Impact
A race condition in the Linux kernel’s adt7470 hardware monitoring driver causes a divide‑by‑zero crash when fan data changes to zero between a validity check and the conversion to RPM. The conflicting updates of the cached fan value trigger the faulty calculation, leading to a kernel panic.
Affected Systems
The flaw is present in any Linux kernel version that includes the adt7470 driver before the patch is applied. No specific kernel releases are identified, so all affected builds containing the module are vulnerable until updated.
Risk and Exploitability
The EPSS score of less than 1% and absence from CISA KEV suggest a low exploitation probability. The CVSS score of 5.5 indicates medium severity, reflecting the kernel crash impact. The likely attack vector requires local execution with sufficient privileges to force fan monitoring operations; however, this requirement is inferred from the nature of the kernel driver and is not explicitly stated in the provided description.
OpenCVE Enrichment
Debian DSA