Impact
The visconti clock driver in the Linux kernel relies on the clk_init_data structure. The driver populates only the members it needs, leaving other mutually exclusive fields uninitialized. When certain kernel configurations that fill the stack with patterns are enabled, the uninitialized fields contain garbage values that the driver later assumes are NULL. The driver dereferences these values during clock registration, causing a kernel panic that takes the system offline. The weakness is an improper initialization of a data structure (CWE‑665).
Affected Systems
All systems running a Linux kernel that includes the visconti clock driver and is compiled with the buggy clk_init_data handling code. The issue exists in any kernel version containing the problematic code path; no specific release version is mentioned, so current kernels and potentially older builds are affected until the fix is applied.
Risk and Exploitability
The probability of exploitation is very low, as reflected by an EPSS score of less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The crash‑based impact delivers a full denial of service for the affected system, yet an attacker would require local access to load the buggy driver or to enable the vulnerable configuration options (CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE). Consequently, the overall risk is moderate to high for availability, with the primary mitigation being to apply the vendor patch or rebuild with the problematic options disabled.
OpenCVE Enrichment
Debian DLA
Debian DSA