Impact
In the Linux kernel sparx5 network driver, a function that causes the kernel to sleep is invoked while a mutex is held inside an atomic context. Atomic contexts are prohibited from sleeping, so the kernel raises a BUG assertion, which can result in a kernel panic. The fault does not expose data, but it can cause system instability and an unplanned reboot. The defect is confined to the sparx5 driver and surfaces when network address multicast tables are synchronized through the ndo_set_rx_mode interface.
Affected Systems
The vulnerability affects all Linux kernel builds that include an unpatched sparx5 driver. The issue exists in any kernel version before the patch that introduces the ndo_set_rx_mode_async callback. As no specific versions are enumerated in the CNA data, all affected kernels are potentially at risk until they receive the fix.
Risk and Exploitability
The EPSS score for this flaw is below 1% and it is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. However, if an attacker can trigger the affected code path—such as by sending crafted multicast traffic—they could force a kernel panic and cause denial of service. The CVSS score is not provided, but the impact is level‑3 since it only produces a crash and not data compromise. The likely attack vector involves local or remote network traffic that triggers the driver’s address sync logic. The risk is therefore moderate, dominated by the potential for DoS rather than an exploitable security breach.
OpenCVE Enrichment