Impact
The Linux framebuffer driver ssd1307fb performs synchronous I2C transfers during damage callbacks while preemption is disabled. This operation attempts to schedule from an atomic context, triggering a scheduling‑while‑atomic bug that causes a kernel crash. The flaw does not provide an execution path for code or privilege escalation; it simply results in a local denial of service whenever the framebuffer is updated. This is a CWE-821: resource management weakness.
Affected Systems
The issue exists in any Linux kernel that includes and loads the ssd1307fb driver. Devices that use this driver, such as Rockchip RK3566 boards running kernel releases like 6.6.0-rc5-rockchip-rk356x, will experience a crash when framebuffer damage occurs. Systems that do not load the module or that use a different display driver are not affected.
Risk and Exploitability
The CVSS score of 5.5 signals moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known. The likely attack vector is local, requiring a user or privilege level that can generate console output or otherwise trigger a framebuffer update; an attacker could force a system reboot or uptime loss by causing the buggy path to execute.
OpenCVE Enrichment
Debian DSA