Impact
The Linux kernel ISST driver contains a null pointer dereference. When a socket load fails, the driver accesses the sst_inst[] array without checking for a null value, which can cause the kernel to crash. This crash results in a loss of system availability and may require a reboot to recover.
Affected Systems
The vulnerability applies to any Linux kernel build that does not contain the recent patch adding the NULL check for sst_inst[]. All system configurations running such kernel versions are at risk, regardless of architecture, as the defect lies in the platform/x86 ISST driver.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a not specify an attack vector, but the failure mode involves a kernel crash triggered the description, it is inferred that exploitation would require local activity that triggers the problematic socket load and likely privileged or elevated permissions to observe the impact.
OpenCVE Enrichment
Debian DSA