Impact
The vulnerability is in the i2c mux subsystem of the Linux kernel. When an adapter registration fails, the driver frees the private data without dropping a reference to the Device Tree channel node that was previously taken. This results in a memory leak that can grow until kernel memory is exhausted, potentially leading to instability or a denial‑of‑service condition. The weakness is a classic resource‑management flaw that affects system availability if the leak can be repeatedly triggered.
Affected Systems
All Linux kernel builds that include the i2c mux driver and contain the unpatched code are at risk. No specific releases or versions are identified, so any kernel containing this code path before the fix is vulnerable.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is supplied. Because the flaw requires the kernel to attempt an adapter registration that fails, it is likely exploitable only from a local privileged context or by malicious firmware that manipulates the device tree. Given the low exploitation likelihood, the overall risk remains moderate relative to higher‑impact flaws, but the potential for resource exhaustion warrants prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA