Impact
A NULL pointer dereference in the Linux kernel IPMI SI driver causes a kernel panic when a Get Device ID command fails. The bug is triggered after a failed registration and occurs when a shutdown callback clears state without marking the interface as shutting down, allowing a retry work item to access freed data. This results in a system crash, disabling the affected system.
Affected Systems
Linux kernel builds that include the ipmi_si driver before the patch commit are potentially vulnerable. All distributions and kernel releases that expose the buggy SI code path could be affected; no explicit version ranges are listed in the available data.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate severity, whereas the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, pointing to a low likelihood of exploitation. The flaw requires an IPMI interface where the BMC fails to return a valid device ID, and the attacker would need to trigger the retry logic, typically via local or remote IPMI access. While it does not provide remote code execution, the kernel panic results in a denial of service.
OpenCVE Enrichment
Debian DSA