Impact
A kernel driver for Rockchip‑Samsung integrated circuits contains a module that incorrectly sets the maximum register offset to 0x10000, one entry beyond the 64 KB register block that is mapped with a 4‑byte stride. When the regmap debugfs interface dumps the register block, the driver tries to read this out‑of‑range address. The read causes a page fault on an unmapped page, provoking a kernel oops. Because the regmap lock remains held, subsequent PHY operations deadlock. This out‑of‑bounds read (CWE‑125) leads to a denial‑of‑service by crashing the kernel and halting further driver activity.
Affected Systems
All Linux kernel builds that contain the unpatched rockchip‑samsung‑dcphy driver are affected. This driver is present in kernel releases before the commit that introduced the fix. Systems that use Rockchip or Samsung integrated hardware and are running a kernel version that does not include the patch are potentially vulnerable. Distribution kernels that have not yet incorporated the upstream change are also at risk.
Risk and Exploitability
The CVSS score of 4.1 indicates medium severity, while the EPSS score is less than 1%, implying a very low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no widespread exploitation has been reported. The likely attack vector is a local privileged user who can access the regmap debugfs interface; the attacker would trigger an out‑of‑bounds read that causes a kernel oops, holding the regmap lock and leading to a deadlock and subsequent denial of service on the affected system.
OpenCVE Enrichment