Impact
During an error that occurs before the accel/rocket task domain is assigned, the driver’s cleanup routine calls the kernel function to release the domain pointer. Because that pointer is null at that time, the call dereferences a null pointer in kernel space, causing the operating system to crash. The crash results in a blanket denial of service for the entire host, as normal kernel operation cannot continue.
Affected Systems
Linux kernel ships containing the accel/rocket driver before the commit that initializes the job domain before cleanup are vulnerable. All distributions and custom kernel builds that have not yet incorporated this patch, or that still use the older driver code, fall into this category.
Risk and Exploitability
The CVSS score of 5.5 classifies this flaw as moderate severity, while the EPSS score of <1% suggests a very low chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits. Based on the description, it is inferred that an attacker would need local access to the accel/rocket device’s ioctl interface and be able to provoke the error that triggers the null dereference in the cleanup path.
OpenCVE Enrichment