Impact
In the Linux kernel’s Industrial I/O subsystem, the m62332 digital‑to‑analog converter driver contains a logic error that mishandles the Vcc regulator’s reference counter. Each time a non‑zero value is written, the regulator is enabled again without checking its current state, and a zero write disables it only once. On repeated non‑zero writes the reference count can exceed one, while a subsequent zero write decrements it only once, leaving the count never zero. The regulator therefore stays powered indefinitely, consuming power and potentially causing hardware wear or failure. Such uncontrolled power consumption can lead to a denial of service or premature battery depletion in portable devices.
Affected Systems
Any Linux kernel installation that includes the m62332 driver is affected, regardless of version. The advisory lists the kernel as the impacted vendor and does not provide a specific version range, so all builds that compile the m62332 driver without the referenced patch are vulnerable.
Risk and Exploitability
Exploitation requires write access to the device node associated with the m62332 DAC, which typically demands local or privileged privileges. The EPSS score is reported as less than 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, systems that rely on precise regulator control—especially battery‑powered or safety‑critical devices—face significant risk from indefinite regulator activation.
OpenCVE Enrichment
Debian DLA
Debian DSA