Impact
A flaw in the Linux kernel's device property handling allows the function that iterates over fwnode children to enter an infinite loop when a primary fwnode references a secondary fwnode with more than one child. The loop repeatedly outputs the same sequence of child nodes, consuming CPU cycles without terminating, which can cause a denial of service by exhausting processor resources on affected systems.
Affected Systems
All Linux kernel configurations that use fwnode device property structures with secondarywnode_get_next_child_node logic before the fix are affected. vulnerability exists in any distribution that has not yet incorporated the commit that prevents the infinite loop.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score remains <1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is inferred to be local or privileged; an attacker would need the ability to influence firmware or driver execution that constructs the fwnode hierarchy. Exploitation requires modifying or injecting a secondary f elevated access to the system. Because the flaw depends on kernel internals and device drivers, and no public exploit is known, the risk remains low probability but can cause severe denial of service when triggered.
OpenCVE Enrichment
Debian DSA