Impact
The vulnerability is a device reference leak in the Linux kernel’s remoteproc subsystem when a lookup for an SCP device fails. The kernel retains a reference to the device after the lookup without releasing it, causing an unpaired reference count. This leakage can lead to gradual consumption of kernel memory resources.
Affected Systems
All builds of the Linux kernel that include the remoteproc subsystem and have not yet incorporated the referenced patch are affected, regardless of distribution or kernel version. The flaw is present before the commit that fixes the reference release.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score of less than 1 % shows a very low expected exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. While the description does not specify a remote attack vector, the likely scenario involves a local or privileged entity repeatedly triggering the failed SCP lookup to cause reference accumulation. No exploitation path to arbitrary code execution or data exfiltration is described in the supplied data.
OpenCVE Enrichment
Debian DSA