Impact
The vulnerability resides in the Linux media video-i2c subsystem, where the kthread_run() function incorrectly returns an error pointer rather than NULL when thread creation fails. The start_streaming() routine preserves this error pointer in data->kthread_vid_cap. A later invocation of start_streaming() mistakenly interprets the non-NULL pointer as a successful start and returns success without actually spawning the thread. When stop_streaming() later encounters this stale error pointer it attempts to stop it via kthread_stop(), leading to an immediate kernel crash. The crash abruptly halts system operation, effectively denying availability services that rely on the media subsystem. The defect is a classic case of missing error handling and dangling pointer usage.
Affected Systems
All Linux kernel releases that contain the bug in the video-i2c subsystem are vulnerable. The specific versions are not enumerated in the advisory; any maintainers or users deploying the affected commits from the kernel series referenced in the advisory should consider their installations at risk. Updates after the defensive commit that clears kthread_vid_cap on failure will eliminate this issue.
Risk and Exploitability
The CVSS base score is not disclosed, but the impact is severe, leading to a kernel panic. The EPSS score is reported as < 1%, indicating a very low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or privileged context that can trigger the media driver (e.g., a malicious application that forces start_streaming() and stop_streaming() calls); the failure becomes evident only when the error path is taken. Given the low exploitation probability but catastrophic impact, a timely update remains critical.
OpenCVE Enrichment
Debian DLA
Debian DSA