Impact
The flaw occurs in the tpm_i2c_nuvoton driver of the Linux kernel. The helper function i2c_nuvoton_wait_for_stat() enables the device interrupt before waiting for the hardware to signal a status change. If the wait operation times out or is otherwise interrupted before the interrupt handler runs, the function returns without disabling the newly enabled IRQ. This leaves an enabled interrupt line in an improper state, causing spurious interrupts to be delivered, consuming kernel resources, and potentially leading to kernel instability or a crash. The weakness is a resource management defect classified as CWE‑772. The primary consequence is a denial‑of‑service condition where the system may become unresponsive or require a reboot.
Affected Systems
Systems that run a Linux kernel containing the unpatched tpm_i2c_nuvoton driver are affected, regardless of distribution. The driver is part of mainline kernels and may be compiled into the kernel binary or loaded as a module. The vulnerability applies to any kernel version prior to the commit that restores the IRQ disable logic. There is no explicit version range provided, so all current and earlier kernels that include this driver without the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity. The EPSS score of less than 1 % suggests a very low probability of exploit in the wild. The vulnerability is not catalogued in CISA KEV. Attack likely requires local or privileged access to initiate a failed read from the TPM device and induce a timeout, after which the unbalanced IRQ could cause kernel instability. Given the low exploitation probability, the overall risk is moderate, but any system where the driver is loaded should be prioritized for remediation.
OpenCVE Enrichment
Debian DSA