Impact
The flaw is a NULL pointer dereference in the Linux kernel's powerpc/kexec_file component, specifically in the kexec_extra_fdt_size_ppc64 function. When no reserved memory regions exist, get_reserved_memory_ranges can return 0 and leave rmem unallocated, causing a kernel panic when rmem->nr_ranges is accessed. This results in a denial‑of‑service condition, as the kernel crashes.
Affected Systems
Affected systems are all Linux distributions running the Linux kernel that have not yet updated to the version containing the null‑check. The exact version ranges are not enumerated in the advisory, so any kernel prior to the patch that includes the unguarded rmem access is potentially vulnerable. All architectures using the powerpc/kexec_file code path are at risk.
Risk and Exploitability
The vulnerability requires privileged access to invoke kexec or to configure memory ranges; it is not a remote code execution vector. The EPSS score of <1% indicates low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to a local denial of service via a kernel panic, so the overall risk is moderate but mitigated by the low exploitation probability.
OpenCVE Enrichment
Debian DLA
Debian DSA