Impact
The vulnerability causes the kernel to enter an infinite loop when it encounters an invalid value supplied via the eisa_irq_edge command‑line parameter. The eisa_irq_setup() function prints an error but does not advance its parsing position, so the same bad value is repeatedly parsed, preventing the boot sequence from progressing. The result is a denial of service because the machine fails to boot and remains stuck.
Affected Systems
Linux kernel versions on the parisc architecture that support the eisa subsystem are affected. Any kernel build that includes the eisa infrastructure is vulnerable when an invalid eisa_irq_edge value is passed. No specific version range was identified.
Risk and Exploitability
The CVSS score is not disclosed, but the EPSS score is reported as less than 1 %, and the vulnerability is not listed in CISA KEV, indicating a low likelihood of widespread exploitation. The likely attack vector is local or requires the ability to modify kernel boot arguments – for example through a physical console, a compromised bootloader, or embedded firmware that injects malformed eisa_irq_edge values. Successful exploitation would only halt the boot process, resulting in a system‑wide denial of service without compromising data.
OpenCVE Enrichment
Debian DLA
Debian DSA