Impact
The Linux kernel contains a flaw in the IRQ domain activation routine for AST2700 interrupt controllers. The routine calls a function that allocates memory with GFP_KERNEL while the interrupt lock is held and interrupts are disabled. Kernel code must not request new memory in such a context, and doing so can trigger an OOPS or crash. An attacker that can influence the interrupt configuration could cause a kernel panic, resulting in a denial of service for the affected system.
Affected Systems
Any installation of the Linux kernel that includes the ast2700‑intc interrupt controller driver, regardless of distribution, is affected. The CVE references point to commits in the upstream kernel repository, so the issue applies to all kernel versions prior to the fix. No specific version range is listed in the CVE data, so users should treat all earlier kernel releases that contain the code as vulnerable.
Risk and Exploitability
The EPSS score for this vulnerability is reported as less than 1 %, indicating a very low probability that it will be actively exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog. With no publicly available exploit and the need for local kernel access to trigger the fault, the overall risk remains low for typical end‑users, but the impact of a successful exploit—a unprivileged kernel crash—could be severe for systems that rely on high availability.
OpenCVE Enrichment