Impact
The Linux kernel media driver mtk-mdp3 contains a flaw that can cause a NULL pointer dereference when a sensor component (SCP) lookup fails and the driver has not yet been bound. The fault causes a kernel panic, leading to a system reboot or loss of service. This is a classic denial‑of‑service vulnerability.
Affected Systems
All Linux kernel distributions that ship the mtk-mdp3 media platform driver are affected. No specific version range is provided, so the issue may exist in any kernel release that lacks the fix commit.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation in the wild. Based on the description, it is inferred that the attack would require local privileged execution to trigger the path that forces an SCP lookup; remote exploitation is unlikely without additional vulnerabilities. While the impact is limited to a kernel crash, the severity of a denial‑of‑service event remains high for affected hosts.
OpenCVE Enrichment
Debian DLA
Debian DSA