Impact
The flaw triggers when an ancillary media link fails to create, leading to list_del() being called on a list element that has not yet been linked. Because the list pointers are NULL, this results in a NULL pointer dereference that can cause a kernel panic. The bug is disallowed by proper handling of link errors and would allow an attacker with local access that can force link failure to destabilize the system. It falls under the CWE‑476 category of Null Pointer Dereference.
Affected Systems
The vulnerability is present in the Linux kernel's media subsystem, specifically the v4l2‑async component. No specific version range is disclosed in the advisory; therefore any kernel version that includes the v4l2‑async media code before the audit commit may be susceptible. The vendors identified are the Linux kernel maintainers; the full CPE string indicates the Linux operating system kernel.
Risk and Exploitability
The EPSS score is less than 1 % indicating a very low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. The failure path is local to the device driver, so remote exploitation is unlikely unless an attacker can cause the driver to link a media device. No CVSS score is provided, but the potential kernel crash implies a high severity scenario if an attacker could trigger the failure, although the actual exploitation likelihood appears low.
OpenCVE Enrichment
Debian DLA
Debian DSA