Impact
This vulnerability is a memory leak in the Linux kernel's platform/x86 int1092 module. The sar_probe() function fails to free the device_mode_info structure allocated in parse_package() when certain error conditions occur. The leak can grow unboundedly, consuming system memory and potentially leading to degraded performance or crashes. It is an example of CWE-772: Improper Release of Resources. No immediate code execution or privilege escalation is possible, but availability is impacted.
Affected Systems
All Linux kernel builds that include the platform/x86 int1092 module are affected. This encompasses mainstream distributions running x86 architectures on servers, desktops, and embedded devices. Any system running a kernel that contains this module is susceptible, regardless of its operational role.
Risk and Exploitability
The CVSS score of 4.4 rates the issue as moderate, focused on availability. The EPSS score of <1% indicates low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would require a local or privileged user to repeatedly invoke the sar_probe path—possibly via the int1092 device interface—to exhaust memory. The default attack vector is thus local; remote exploitation is unlikely because the module operates in kernel space and no external input is processed.
OpenCVE Enrichment