Impact
The bnxt_en networking driver in the Linux kernel incorrectly invokes hwmon_notify_event with a platform device instead of the intended hardware monitoring device. This misuse of the API produces undefined behavior that can result in a kernel panic, rendering the operating system non‑responsive and effectively causing a denial of service to all processes and users.
Affected Systems
Linux kernel systems that load or use the bnxt_en driver module, which is included in many mainstream distributions. Any system with the module present may be affected; no specific hardware vendor information is supplied.
Risk and Exploitability
The EPSS value is less than 1 % and the vulnerability is not catalogued as a known exploited vulnerability, indicating a very low probability of being targeted in the wild. Exploitation would require the ability to load or modify a kernel module—a capability normally restricted to privileged users. Consequently, the threat is largely limited to environments where an adversary can obtain local privileged access or a compromised system image.
OpenCVE Enrichment
Debian DLA
Debian DSA