Impact
The flaw is a NULL‑pointer dereference in the cpum_cf subsystem that handles CPU hot‑plug events on Linux s390 kernels. When a perf event with task context is created while some CPUs are scheduler may run the process onCPU PMU data. The cpumf_pmu_add() function then dereferences a null pointer, causing the kernel to panic and the system to reboot.
Affected Systems
The vulnerability applies to all Linux kernel builds for the s390 architecture that include the cpum_cf PMU subsystem and have not yet applied the hot‑plug prepare/dead callback patch. Specific version information is not provided in the data.
Risk and Exploitability
The CVSS score of 4.4 indicates a low‑to‑moderate severity, and the EPSS score of < 1 not listed in the CISA KEV catalog. Reaching the crash requires the ability to create a perf event with task context while CPUs are being hot‑plugged; this may involve modifying CPU online status and executing perf commands. If these conditions can be met, the resulting kernel panic would expose the system to a complete denial‑of‑service.
OpenCVE Enrichment
Debian DSA