Impact
The octeontx2-pf driver contains a NULL pointer dereference where the af_xdp_zc_qidx bitmap is accessed without a NULL check. This bug is triggered during representor initialization in devlink eswitch mode and can cause an oops leading to a kernel panic. The resulting system downtime is the only documented impact; no privilege escalation or information disclosure is referenced in the CVE description. The weakness corresponds to a missing null‑check before bitmap operations (CWE‑476).
Affected Systems
The vulnerability exists on any Linux kernel that runs on an OcteonTX2 SoC before the fix commit 7e33c6bd049b532d2ec4916895ef07e538bed905 is incorporated. It applies to all Linux variants deployed on OcteonTX2 hardware, regardless of vendor, since the kernel source code is the same. Systems using a newer kernel that includes the patch are no longer affected.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV, indicating an extremely low probability of active exploitation. Based on the description, it is inferred that the attack vector would require local access to enable devlink eswitch mode or trigger representor initialization, which results in a kernel panic that causes a high impact denial of service. No publicly known exploits exist at present, so the primary risk is the potential for accidental system crashes during normal operation. Nevertheless, the high severity of the kernel crash warrants patching when available.
OpenCVE Enrichment