Impact
A flaw in the Linux kernel’s pm8001 SCSI driver causes the rollback logic to use the wrong index when freeing MSI‑X interrupts. During an error, the code passes an invalid IRQ/dev_id pair to free_irq(), leaving earlier handlers registered. The effect is that interrupts remain bound to old handlers, which can lead to erratic interrupt delivery, degraded performance, or a system crash. The vulnerability surfaces only when request_irq() fails, so it may be exploitable in a target environment where device initialization can be forced to error.
Affected Systems
All Linux kernel builds that include the pm8001 SCSI driver prior to the commit that corrects the rollback index. The exact kernel versions are not listed, but the issue was identified in the stable development tree. Updating to a kernel that incorporates the referenced commits resolves the problem.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present, and the vulnerability is not yet in the CISA KEV catalog. Likely attack vectors involve local privileged users who can manipulate the pm8001 device to trigger request_irq() failure, potentially allowing denial of service or escalating privileges if the handler was privileged. The mitigation relies on applying a kernel update that uses the correct vector index in the rollback loop.
OpenCVE Enrichment
Debian DLA
Debian DSA