Impact
In the Linux kernel, the RAVB driver contains a null‑pointer dereference that occurs when the Precision Time Protocol (PTP) clock is queried before it has been opened or after a registration failure. The PTP clock is not yet available, so accessing its index can pointer in the driver structure. The flaw is a classic CWE‑476 vulnerability that can trigger a kernel fault and bring the system down.
Affected Systems
All Linux kernel configurations that compile the RAVB driver are affected. Vendors listed by the CNA are Linux:Linux, meaning any distribution that ships the Linux kernel with the RAVB module compiled is susceptible. This includes the default kernel configuration used by many distributions.
Risk and Exploitability
The CVSS base score of 7.8 denotes high severity. The EPSS probability is reported as less than 1 %, indicating an extremely low likelihood of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. An attacker would typically need local or elevated privileges to interact with the RAVB interface, allowing them to trigger the vulnerability and cause a loss of availability via a crash. Remote exploitation is unlikely without additional local compromise.
OpenCVE Enrichment
Debian DSA