Impact
A reference leak exists in the Linux kernel media subsystem’s v4l2_fwnode_parse_link function. The kernel acquires a remote endpoint reference through fwnode_graph_get_remote_endpoint() but fails to release it on successful completion. Each call therefore increments the reference count irreversibly. Over time, repeated invocations can exhaust available reference slots, causing failures in subsequent operations that depend on those references and potentially leading to a kernel resource exhaustion scenario. The flaw does not provide privilege escalation or confidentiality disclosure; its primary impact is service interruption through denial of service.
Affected Systems
All Linux kernel builds that include the media subsystem and contain the vulnerable v4l2_fwnode_parse_link implementation before the commit adding the missing fwnode_handle_put() call are affected. The issue is present across all distributors that ship such kernels, not limited to any vendor-specific variant.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% indicates a very low probability of active exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that exploitation requires normal kernel operation that parses V4L2 firmware node links, so the attack vector is local via routine device usage. The severity is limited to resource exhaustion leading to service disruption; no code execution or privilege escalation can be achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA