Impact
The Linux kernel pinctrl driver for spacemit contains an incorrect NULL check that permits a NULL pointer dereference and causes the PAD configuration for pin 0 to be skipped. This flaw can trigger a kernel fault during configuration or silently ignore essential pin settings, leading to system instability or malfunction. The weakness is classified as a NULL pointer dereference (CWE‑476).
Affected Systems
The vulnerability resides in the Linux kernel’s spacemit pinctrl driver and affects all kernel versions that include this driver before the patch was applied. The fix was introduced in kernel commits 09c816e5c4d3a8d6d6e4b7537433e5e98505d934 and 7a551951ebeb5b3f05bdb04a73d4593869c984c4. Consequently, any Linux installation running a pre‑patch kernel that utilizes the spacemit driver is susceptible.
Risk and Exploitability
No CVSS score, EPSS score, or KEV listing is available, indicating that publicly documented exploitation is not known. The flaw likely requires local access to the kernel space to trigger the misconfiguration or crash, making it a low‑probability attack. Nonetheless, the potential for a kernel panic or subtle device misbehavior warrants prompt remediation.
OpenCVE Enrichment