Impact
The vulnerability is a null‑pointer dereference in the Linux kernel’s s390 DASD driver. When the driver registers a sysfs callback before allocating the device->private structure, an unprivileged user can read a world‑readable attribute during that narrow window and, leading to a kernel panic. This results in a denial of service that brings the entire system down.
Affected Systems
All Linux kernel builds containing the s390 DASD driver before the patch that adds guard checks are vulnerable. This includes any distribution whose kernel version packages the driver before the commit that protects sysfs callbacks, regardless of the device’s operational status, as the callbacks remain world‑readable.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity; the EPSS score of <1% reflects a very low likelihood of exploitation, and the flaw is not included in CISA’s KEV catalog. Exploitation requires an unprivileged user to access a specific sysfs attribute during the brief allocation window created by dasd_generic_set_online. Although the opportunity is narrow, the impact of a kernel panic is severe, compromising system availability.
OpenCVE Enrichment
Debian DSA