Impact
A flaw in the Linux kernel’s PCF8563 clock driver causes it to register a clock provider during device bind but never unregister that provider during unbind. Each bind/unbind allocates a provider structure, holds a reference to the device tree node, and adds the provider to a global list, with none of these resources released when the device is unbound. Over repeated bind/unbind cycles—such as during hotplug events or module reloads—these orphaned structures accumulate, consuming kernel memory and increasing the reference count of the node. The vulnerability does not disclose data or enable arbitrary code execution but can lead to resource exhaustion and eventual system instability or a denial‑of‑service outcome once memory limits are reached. The weakness aligns with a memory/resource leak type of vulnerability.
Affected Systems
All Linux kernel releases containing the PCF8563 RTC driver before the upstream fix is applied. The exact affected kernel versions are not enumerated in the CVE record, but the issue is present in every kernel that includes the unbound driver implementation.
Risk and Exploitability
The CVSS score is unspecified, but the EPSS score indicates exploitation odds below 1%, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector requires local privilege to force reloads or trigger device hotplug events that cause the driver to unbind, making remote exploitation improbable. Consequently, the practical risk is a low‑to‑moderate likelihood of a denial‑of‑service event in environments where many RTC instances are bound and unbound over time.
OpenCVE Enrichment
Debian DLA
Debian DSA