Impact
In the Linux kernel the cedrus VPU driver contains a memory leak in the initialization of its V4L2 control handler. The handler is set up before memory for the control structure is allocated; if the allocation fails the function returns an error but does not free the previously allocated handler, leaking kernel memory. Repeated or forced failures could gradually exhaust memory, destabilize the kernel, and lead to a denial‑of‑service condition.
Affected Systems
The issue appears in the Linux kernel, affecting all distributions that ship the cedrus driver prior to the patch that fixes the leak (confirmed present in v7.1.1 and earlier). No specific vendor or product version lists are provided beyond the general Linux kernel.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a very low probability of exploitation. The impact is local; an attacker with the ability to trigger the cedrus driver initialization repeatedly could attempt to force a memory exhaustion state. However, the low exploit probability combined with the lack of public exploitation makes the threat moderate at best.
OpenCVE Enrichment
Debian DLA
Debian DSA