Impact
The vulnerability occurs when virtio‑RTC alarm requests wait indefinitely for a buffer return, because the driver holds ops_lock while blocking. The missing timeout causes the removal routine to deadlock on ops_lock, which can result in a stuck kernel thread. This behavior is inferred to produce a denial‑of‑service condition, as the hanging thread can stall system operations.
Affected Systems
This flaw affects the virtio‑RTC driver implementation in the Linux kernel. Any distribution or system running a Linux kernel that includes the unpatched virtio‑RTC code is at risk; no specific version range is listed, so all kernels prior to the patch that still use this module are potentially vulnerable.
Risk and Exploitability
The EPSS score is under 1 % and the vulnerability is not listed in CISA KEV, indicating a low current exploitation probability. The likely attack vector requires privileged or virtual‑environment control to force a virtio device to be removed or break. The post‑patch fix introduces a 60‑second timeout to prevent indefinite blocking, reducing the impact considerably if the patch is applied.
OpenCVE Enrichment