Impact
The vulnerability lies in the RAVB network driver of the Linux kernel where a null pointer dereference can occur when a PTP clock is queried before it has been opened or after a failed registration. The buggy code may dereference a NULL pointer or an error pointer, causing the kernel to fault. As a result, a local or privileged attacker could trigger a kernel crash, leading to an immediate denial of service for the affected host.
Affected Systems
All Linux kernel builds that include the unpatched RAVB driver are affected. The issue is present in the default kernel configuration used by most distributions prior to the fix. Vendors listed in the CNA data include Linux:Linux.
Risk and Exploitability
The CVSS score of 5.9 reflects a medium severity assessment. The exploitability score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector requires local or privileged access to instantiate the RAVB interface, after which an attacker could use the faulting path to crash the system.
OpenCVE Enrichment