Impact
The vulnerability is a NULL pointer dereference in the Linux ngbe network driver when interrupt handling is performed in non‑MSI‑X mode. This flaw causes the kernel to crash, resulting in a denial of service because the entire system becomes unstable until rebooted.
Affected Systems
The issue affects any Linux kernel that includes the ngbe driver and has not yet been updated to the patched version. All vendors that ship the standard Linux kernel are affected.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower probability of widespread exploitation. The likely attack vector would involve interaction with the affected network device, potentially through local privilege escalation or crafted traffic that triggers the driver’s non‑MSI‑X interrupt path. Because the flaw leads only to a crash rather than code execution, it poses a moderate risk to availability but not to confidentiality or integrity.
OpenCVE Enrichment