Impact
The vulnerability in the Linux kernel’s DRM panel EDP driver keeps a reference to an I2C adapter when the probe fails or when the device tree incorrectly uses the ‘ddc‑i2c‑bus’ property, leaving the adapter allocated longer than necessary. This leak can accumulate over time, causing kernel reference counts and memory allocation to grow until the I2C subsystem is unable to function properly, which is a direct drain of kernel resources.
Affected Systems
All Linux kernel deployments that include the DRM panel EDP driver are potentially affected. No specific version is listed in the advisory; the issue was addressed in commit 0259846b15a665c6762a86b3fa0eb8b674b35d1c and appears in subsequent kernel releases.
Risk and Exploitability
No CVSS score has been published for this issue. The EPSS score is below 1%, indicating a very low probability of exploitation in the wild. The vulnerability has not appeared in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require an attacker to have the ability to repeatedly trigger probe failures or alter device tree configuration, which typically implies local or privileged access.
OpenCVE Enrichment
Debian DLA
Debian DSA