Impact
In the Linux kernel’s ACPI/APEI/ghes module, the CXL CPER work registration helpers lock with a spinlock guard(), which leaves local interrupts enabled. When a GHES error interrupt occurs on the same CPU, the interrupt handler attempts to acquire the same lock with irqsave, causing the handler to spin while its preempted lock holder waits. This circular wait results in a deadlock that stalls the kernel, potentially rendering the system unresponsive. The flaw is a classic priority‑inversion deadlock identified as CWE‑833.
Affected Systems
All installations of the Linux kernel that compile the ACPI/APEI/ghes component with CXL CPER support and have not applied the commit converting the locks to raw_spinlock_t are affected. The vulnerability applies to every Linux kernel version built prior to the patched release, regardless of vendor distribution.
Risk and Exploitability
The CVSS score of 4.4 reflects low severity, and the EPSS score of less than 1% indicates that exploitation is unlikely. Because the deadlock requires a GHES interrupt, which is typically generated by a hardware fault or by privileged local firmware actions, the attack vector is local and non‑remote. The vulnerability is not listed in CISA’s KEV catalog. Overall, the risk to an attacker is low; the primary impact is a kernel stall rather than information disclosure or remote compromise.
OpenCVE Enrichment
Debian DSA