Impact
A race condition in the Linux kernel’s fbdev omapfb panel DSI CM driver allows a driver to register a display before initializing the mutex that protects its callback data. When another component invokes a callback during registration, it may acquire this uninitialized lock, leading to undefined behavior and a kernel crash. The flaw is identified as CWE-908, a race condition.
Affected Systems
The vulnerability affects all Linux kernel builds that include the unpatched omapfb panel DSI CM driver. The publicly available information does not list specific kernel versions, so any kernel containing the unmodified driver code prior to the patch is considered vulnerable.
Risk and Exploitability
The high‑severity CVSS score of 8.4 indicates significant impact. The EPSS score of less than 1% reflects a low probability of exploitation, and the flaw is not present in the CISA KEV catalog. Based on the description, the likely attack vector is a local or privileged user capable of loading or interacting with the omapfb driver, potentially causing a denial of service through kernel crash.
OpenCVE Enrichment
Debian DSA