Impact
The apple‑soc cpufreq driverP) tables that are loaded from firmware when driver initialization fails, leading to stale kernel memory entries and resource exhaustion. This flaw does not grant direct confidentiality or integrity violations; it merely depletes system resources until the driver is reloaded or the machine is rebooted.
Affected Systems
All Linux kernel releases that contain the unpatched apple‑soc cpufreq driver are subject to this issue. Any kernel version prior to the patch remains at risk until a newer kernel incorporating the fix is installed.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability requires local kernel interaction during driver initialization; no remote attack vector or privilege escalation is documented. The attack vector is inferred driver load and cleanup paths. Since the issue is not listed in the CISA KEV catalog, the overall risk is that a malicious local user or process could deplete kernel resources by triggering repeated failed initialization or unloads of the driver.
OpenCVE Enrichment
Debian DSA