Impact
The vulnerability occurs in the Linux SPI subsystem when a DMA mapping for a device message partially fails. After a successful transmission mapping, the code clears the transmission flag but mis‑tracks ownership of the device pointers; when a subsequent mapping fails, these pointers remain stale or NULL. The later unmapping logic then attempts to unmap using that NULL or stale pointer, causing the DMA unmap function to dereference a NULL pointer before any safety checks. This results in a kernel oops and a crash, providing attackers with a denial‑of‑service capability but no direct privilege escalation or code execution.
Affected Systems
All Linux kernel images that have not incorporated the commit referenced in the advisory are affected, regardless of distribution. The bug is present in any build that still uses the legacy SPI DMA mapping logic before the fix commit, and the issue is not limited to a specific kernel version in the supplied data.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity. The EPSS score is reported as less than 1 %, implying a low expected exploitation likelihood in typical environments. The vulnerability is not listed in the CISA KEV catalog, but the high severity warrants prompt remediation. Based on the description, it is inferred that exploitation would require the attacker to provoke a failure in an SPI DMA mapping operation, which generally requires privileged code or control over the SPI hardware. Therefore, the likely attack vector is limited to systems with exposed SPI drivers or those that allow an attacker to trigger mapping failures. The risk is higher for environments where SPI drivers are active and unmonitored.
OpenCVE Enrichment
Debian DLA
Debian DSA