Impact
A race condition exists in the Linux kernel driver octeontx2-vf during the probe and removal phases. The driver initializes a workqueue after registering the network device, so if ndo_set_rx_mode queues work before the workqueue is ready, the kernel may attempt to execute a task on a NULL workqueue, leading to a kernel panic. The resulting crash denies service to the entire system.
Affected Systems
Systems running the Linux kernel that load the octeontx2-vf driver are affected. No specific kernel versions are enumerated in the available data, so the vulnerability applies to all deployments that include this driver.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The lack of a public CVSS score limits precise severity quantification, but kernel crashes are high impact. The likely attack vector is local; an attacker with sufficient privileges to influence the driver’s probe or removal sequence could trigger the crash, resulting in a denial‑of‑service.
OpenCVE Enrichment