Impact
In the Linux kernel, the fsl‑edma tracing code stores a pointer to a struct fsl_edma_engine within a ringbuffer and dereferences that pointer when a trace log entry is printed. If the engine has already been freed or its memory relocated when the log is generated, the dereference accesses an invalid address, causing a kernel panic. An attacker can trigger the crash by injecting a malformed event into the fsl_edma trace buffer through the /sys/kernel/tracing interface, resulting in a denial‑of‑service for the entire kernel and any user processes.
Affected Systems
The flaw exists in any Linux kernel that includes the fsl edma driver with tracing enabled, regardless of distribution. All current kernels before the fix are affected, as the issue was corrected by adding a membase field for log output and avoiding the pointer dereference. Distributions shipping those kernels without the patch are vulnerable until a newer kernel release is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and it requires local privileged access to the tracing interface (root or similar) to inject events, making it an attack vector that is local rather than remote. A successful exploit would crash the kernel, causing a system‑wide denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA