Impact
The bug in the Linux kernel’s ipa driver (CWE‑821) causes the transmit queue to be stopped and resumed work to run while the modem is still transitioning to an active power state. The wake is consumed too early, resulting in a function that returns without scheduling further wake actions. Consequently, the queue never restarts, packets accumulate in the kernel’s queuing discipline, and the interface remains permanently stopped. Because the ipa network device does not register a transmit‑timeout routine, no watchdog can recover the stalled interface, yielding a persistent denial of service to the cellular data path.
Affected Systems
The flaw resides in the Linux kernel’s ipa network subsystem, which is part of the Linux kernel. Devices that employ an ipa‑enabled modem—such as the Fairphone 6’s SM7635—can experience the stall if they run an unpatched kernel version. Thus, Linux kernel installations that include the affected ipa driver are potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity. The EPSS score is below 1%, indicating that exploitation is unlikely at present. The vulnerability is not listed in CISA KEV, and no public exploits are known. Based on the description, it is inferred that an attacker could trigger the race condition by repeatedly suspending and resuming the modem’s power state, but such a scenario has not been observed. The denial of service will persist until the system is rebooted or the kernel receives the patch. The lack of an active exploit or watchdog makes the threat primarily a low‑probability local failure rather than an active network attack.
OpenCVE Enrichment
Debian DSA