Impact
The kernel bug causes a null pointer dereference when reading the NIX TM tree via /sys/kernel/debug/octeontx2/nix/tm_tree if the transmit‑queue context is not allocated. This leads to a kernel oops that silently crashes the system. The weakness is a null dereference (CWE‑476) and the result is a local denial of service. No remote code execution or privilege escalation is reported.
Affected Systems
The flaw is present in the Linux kernel's octeontx2-af driver, which is used by all Linux distributions that ship the octeontx2 driver for the Chelsio/TX family of accelerators. The vendor data lists Linux:Linux and the CPE covers the entire Linux kernel. No specific kernel version is listed, so any kernel build that includes this driver before the fix is affected.
Risk and Exploitability
The CVSS score is not shown in the advisory, but the EPSS score is very low, indicating that widespread exploitation is unlikely. The debugfs file is typically accessible only to root or kernel module users, so the attack vector is local. The vulnerability is not listed in the CISA KEV catalog, so there are no documented active exploits. The risk level is moderate but should be mitigated promptly to avoid accidental system crashes.
OpenCVE Enrichment
Debian DLA
Debian DSA