Impact
During the probe phase of the Realtek RTL83xx driver, the kernel calls the non‑sleeping gpiod_set_value() function to assert and deassert a reset GPIO. When the reset line is provided by a sleeping controller, such as an I2C I/O expander, this usage triggers a warning in the kernel log. The patch replaces gpiod_set_value() with gpiod_set_value_cansleep(), which is safe in sleeping contexts and eliminates the warning.
Affected Systems
All Linux kernels that include the Realtek RTL83xx driver and the rtl83xx_reset_assert() and rtl83xx_reset_deassert() helpers, starting with kernel version v6.9 and later, are affected. Older stable kernels that have hard‑coded gpiod_set_value() calls in the driver are also vulnerable if they contain the probe code that exercises those calls.
Risk and Exploitability
The CVSS score of 4.1 reflects a low‑to‑moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to influence the probe sequence of the Realtek device, possibly through physical access, firmware manipulation or other means that trigger the probe path; this inference is made because the description does not specify a direct attack vector.
OpenCVE Enrichment
Debian DSA