Impact
In the Linux kernel media driver, setting the EOS flag causes a firmware command that writes to VPU registers while the device is runtime suspended. Because the hardware is powered down, the SoC raises an asynchronous SError that panics the kernel, leading to a system crash. The weakness is an improper use of runtime power management that allows register access in an invalid power state.
Affected Systems
The flaw resides in the Linux kernel's media:chips-media wave5 driver. All kernel releases that contain this driver and have not applied the recent patch are affected. The vendor is the Linux kernel community. The issue can occur on any platform that implements the wave5 driver and its VPU subsystem.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low likelihood of exploitation at present. The flaw is not yet listed in the CISA KEV catalog. Attackers would need local access to issue V4L2 commands to trigger the defect, so the risk is confined to privileged or local users. The impact is a full kernel crash, resulting in denial of service. Although a CVSS score is not provided, the severity warrants prompt remediation.
OpenCVE Enrichment