Impact
The Linux kernel’s virtio balloon driver had no shutdown handler; when the generic virtio bus shutdown path ran during device_shutdown(), the balloon’s asynchronous work remained active. This caused a WARN_ON_ONCE after the device was broken, and if panic_on_warn is enabled, the result is a kernel panic. The failure prevents the system from booting into a new kernel via normal reboot or kexec based upgrade, effectively denying service for the affected host.
Affected Systems
All Linux kernel installations that ship with the virtio_balloon driver prior to the patch, regardless of distribution, are affected. The problem is mitigated by applying the official kernel update that adds a shutdown handler that quiesces the balloon before resetting the device.
Risk and Exploitability
The vulnerability is not currently in the CISA KEV list and has an EPSS score below 1%. Exploitation does not require active attacker control; the issue surfaces automatically on normal device shutdown or system reboot, making it a low effort, high impact denial of service. The CVSS metric is not provided, but the impact warrants prompt mitigation.
OpenCVE Enrichment