Impact
The vulnerability arises during the initialization of a vdpa_sim device in the Linux kernel. If kthread_run_worker() fails, the vdpasim->worker member is left as an ERR_PTR. A subsequent call to vdpasim_free() then unconditionally passes this erroneous pointer to kthread_destroy_worker(), causing a general protection fault that brings down the kernel. The weakness is an unchecked use of an error value that is treated as a valid pointer, leading to a crash and loss of availability for the system.
Affected Systems
Any Linux installation that builds in the vdpa_sim subsystem and has not yet applied the patch is affected. No specific kernel release or version is listed, so all kernels containing this code prior to the fix are at risk.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. Attackers would need the ability to instantiate a vdpa_sim device, which generally requires privileged access or elevated kernel permissions. If utilized, the flaw would terminate the kernel, providing a denial of service but not directly allowing unauthorized code execution. The risk, while low in terms of exploit likelihood, remains significant because a crash can disrupt critical services.
OpenCVE Enrichment
Debian DLA
Debian DSA