Impact
TheMI message interface, if an error is encountered, the work scheduled to run is not properly cancelled. This oversight can lead to dangling references or usage of freed resources, potentially triggering a kernel panic or memory corruption, thus denying service. The flaw is identified as a use‑after‑free bug under CWE‑772.
Affected Systems
All Linux kernel builds that include the IPMI subsystem are affected, including the mainstream kernel. All kernel versions prior to the commit that fixes the faulty cancellation logic are considered at risk.
Risk and Exploitability
The CVSS base score of 8.4 indicates a high severity assessment. The EPSS score is < 1%, indicating a very low exploitation probability. It is inferred that the attack vector is local, requiring privileged access to load or modify kernel modules during system boot or the advisory. Given the kernel-level nature of the flaw, an attacker with sufficient privileges could crash the host but there is no evidence of remote code execution.
OpenCVE Enrichment