Impact
In the Linux kernel’s IPMI subsystem, the function ipmi_add_smi() creates the sysfs files nr_users and nr_msgs before attempting to create maintenance_mode. When the final creation fails, the error path removes only nr_users, leaving nr_msgs registered on a freed IPMI interface. Based on the description, this orphaned sysfs attribute remains exposed under /sys/class/ipmi, allowing userspace programs that can read IPMI sysfs entries to access internal kernel state and possibly sensitive information.
Affected Systems
Any Linux kernel that includes the unpatched ipmi driver is affected. That includes all distributions that ship a kernel version containing this code before the patch was released. The vulnerability is inherent to the kernel source and does not depend on a specific flavor or vendor beyond the generic Linux kernel.
Risk and Exploitability
The vulnerability assigns a CVSS score of 7.8, classifying it as high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the bug is not listed in the CISA KEV catalog. Attackers would need a condition that triggers the maintenance_mode creation failure, which may require privileged kernel execution or specific environmental factors. Based on the description, the exploit path is thus limited to environments where privileged users can read the orphaned sysfs entry, so while the potential impact could be significant, the practical risk remains low in typical non‑privileged deployments.
OpenCVE Enrichment