Impact
The vulnerability arises in the media rc driver sunxi-cir, where a successful rc_register_device registration is not undone when subsequent probe stages fail. The kernel only frees the device structure instead of unregistering the device, leaving the rc device registered and its resources tied up. This can lead to resource exhaustion, potentially preventing new RC devices from being registered and causing denial of service.
Affected Systems
All Linux kernel releases that include the media rc sunxi-cir driver and that have not yet applied the patch are affected. The vendor information lists Linux:Linux, indicating that any distribution shipping the default kernel configuration with this driver is a risk. No specific version numbers are provided, so the issue applies until the fix is made available in a kernel update.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity, and the EPSS score of less than 1% indicates that exploitation is currently unlikely but still plausible. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to trigger a probe failure of the sunxi-cir device, which typically requires local access to the hardware or the ability to load the kernel module. If an attacker can repeatedly cause such failures, they may exhaust the limited device slots and prevent normal operation, resulting in a denial of service. The patch mitigates this by adding an unwind path that performs rc_unregister_device on all error scenarios.
OpenCVE Enrichment
Debian DLA
Debian DSA