Impact
The OMAP SSI driver in the Linux kernel allocates a synthetic HSI controller via hsi_alloc flow. The allocated device does not receive a the DMA API requires a valid dma_mask for every DMA mapping operation. Because the mask is missing, attempts to map DMA buffers with dma_map_sg() or related helpers can cause a kernel crash or generate warnings, leading to a denial‑of‑service for any process using the driver.
Affected Systems
All Linux kernel builds that include the O. The vulnerability is present in any kernel version where the driver is compiled and the DMA API hardening changes are in effect. Vendors that ship kernels with the unpatched driver expose their systems to this risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local: an attacker would need to trigger a DMA mapping operation within the SSI driver, which requires local code execution or a separate kernel flaw that provides such control. Thus the risk is local denial of service, with potential to aid privilege escalation if combined with other weaknesses.
OpenCVE Enrichment
Debian DSA