Impact
The vulnerability exists in the Linux kernel's imx415 media/i2c driver. During the VBLANK operation, if configuring VMAX fails after a runtime PM reference has been acquired, the driver mistakenly returns early and fails to release that reference. This results in a PM reference leak; repeated misuse of the VBLANK path can accumulate unreleased references, potentially degrading kernel performance or causing instability. The description does not mention an explicit denial of service, so the impact is limited to a resource leak and possible kernel instability.
Affected Systems
The flaw resides in the Linux kernel’s media/i2c imx415 driver. Any kernel version that includes this driver before the patch is potentially affected, regardless of distribution. No specific version range is given, so all kernels with the imx415 module are at risk until updated.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The CVSS score is not provided in the source data; based on the described mechanism the likely attack vector is local kernel execution. There is no evidence that an attacker could force a denial‑of‑service or other malicious outcome beyond the resource leak. As a result, risk is considered low while the vulnerability remains unpatched.
OpenCVE Enrichment