Impact
The defect resides in the ethosu device driver within the Linux kernel. When the kernel fails to map the required hardware registers, the probe routine stores an error pointer from devm_platform_ioremap_resource() and later dereferences it through memory‑mapped I/O accessors. This unchecked error pointer leads to a kernel crash, rendering the system unstable. The underlying weakness corresponds to the improper handling of error pointers, a typical instance of a NULL or invalid pointer dereference.
Affected Systems
All currently supported Linux kernel releases that include the ethosu driver are affected, as the vulnerability originates from the kernel source itself. The specific versions are not enumerated in the data, so any kernel with the unpatched ethosu probe logic is vulnerable.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in CISA's KEV catalog, further suggesting limited active exploitation. Based on the description, it is inferred that the attack vector requires local privileged access to load or trigger the ethosu driver, meaning the primary risk is to systems administered by users with sufficient kernel privileges. The impact is a denial of service via kernel panic, but no known code‑execution path exists in the current data.
OpenCVE Enrichment