Impact
In the Linux kernel, an initialization oversight in the dw‑edma driver causes an IRQ handler to be registered with a null back pointer. When a shared interrupt fires, the handler dereferences this null pointer, which results in a kernel crash. The failure leads to a denial‑of‑service condition for the affected system. The weakness is a null pointer dereference, characteristic of improper initialization.
Affected Systems
The affected product is the Linux kernel, specifically the dw‑edma DMA engine driver. No explicit kernel version range is given, so any kernel build that includes this driver before the patch may be vulnerable. Linux distributions that ship the upstream kernel without the update are at risk.
Risk and Exploitability
The available assessment shows a negligible exploitation probability with an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, and no commercial CVSS score is supplied, making detailed severity unclear. Attackers would need local access to trigger the driver’s shared interrupt or rely on a scenario that causes the interrupt to deliver a request, which is typically an administrative or privileged context. The impact remains a system crash rather than arbitrary code execution, based on the kernel’s reaction to a null pointer dereference. Therefore, systems exposed to this driver should treat the vulnerability as low likelihood but potentially disruptive to availability.
OpenCVE Enrichment
Debian DLA
Debian DSA