Impact
In the Linux kernel IIO pressure driver for the dps310 sensor, enumeration via the ACPI HID IFX3100 leads to a NULL pointer dereference during probe, causing a kernel crash and resulting in a denial of service because the operating system becomes unstable or hangs. The weakness arises from dereferencing a device identifier that does not exist in the driver’s device ID table. The crash manifests as a fatal kernel oops that typically forces a reboot, disrupting services on the affected host.
Affected Systems
The vulnerability affects Linux kernels that include the dps310 IIO driver when ACPI enumeration is enabled for devices with the IFX3100 HID. Vendor products involve Linux kernel releases compiled with the dps310 driver; no specific version numbers are provided, so any kernel package containing the driver and ACPI support can be impacted.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, indicating currently low exploitation probability. Despite the absence of an explicit CVSS value, a kernel crash carries a high impact rating. The attack vector is inferred to require either local or privileged access to trigger the ACPI probe for the IFX3100 sensor; remote exploitation is unlikely unless an attacker can influence device enumeration or firmware configuration.
OpenCVE Enrichment
Debian DLA
Debian DSA