Impact
A NULL pointer dereference occurs in the device a per‑CPU pointer, causing a flaw is a classic example of CWE‑476 and results in a local denial of service. The likely attack vector requires an attacker to trigger the per‑CPU allocation failure or otherwise influence kernel memory, typically requiring elevated privileges or a defect in scheduling that forces the allocation to fail. Modest impact on system availability, while the EPSS of <1% shows a very low probability of exploitation in the wild. The flaw is not listed in the would generally require local privileged conditions; once triggered, it leads to a kernel crash that can only be remedied by rebooting. The recent patch introduces a NULL check that fully mitigates the issue.
Affected Systems
All Linux kernel releases that do not include the commit identified in the referenced URLs are affected. The vulnerability applies to generic Linux distributions such as Red Hat, SUSE, Debian, or any vendor that ships the upstream kernel without the patch. Administrators should verify whether their kernel version predates the commit id 0c8f7870ed3ebd512f090d7714cc2c556b9e5c75 and apply the update if necessary.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity. The EPSS score of <1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, further indicating limited threat surface. A local privileged attacker who can force a per‑CPU allocation failure could trigger the kernel crash. The fix prevents the NULL pointer dereference that previously caused the crash.
OpenCVE Enrichment
Debian DSA