Impact
The Linux kernel on s390 machines can reset the wrong PCI function when handling multifunction devices, because the hotplug driver assigns the same pci_slot object to all functions. This logic flaw also causes a memory leak due to unreleased pci_slot objects. The vulnerability therefore results in faulty PCI resets and can degrade system stability or interrupt critical services. The associated CVSS score of 8.4 indicates a high impact, but the EPSS score of less than 1% shows that exploitation is currently considered unlikely. The vulnerability is not listed in CISA’s KEV catalog.
Affected Systems
The flaw affects the Linux kernel on s390 hardware. No specific kernel release or version is identified in the advisory, so all s390 deployments running a kernel that supports PCI hotplug are potentially susceptible. The advisory references the core kernel Git repository in which the patch is applied.
Risk and Exploitability
The attack vector likely requires privileged local access or kernel-level compromise to trigger the wrong reset of a PCI device. Exploitation would involve invoking the hotplug driver’s reset_slot() interface on a target function, which could result in an incorrect hardware reset and memory leak. Because the weakness is internal to the driver logic, remote exploitation is improbable without additional local privileges. The low EPSS score reflects this limited exposure. Nonetheless, the high CVSS score suggests that once exploited, the effect on availability or integrity could be serious.
OpenCVE Enrichment