Impact
An invalid pointer dereference occurs in the Linux kernel’s dpll subsystem when the last owner of a dpll device unregisters while another driver still holds a pin on it. The device object remains alive with an empty list of registrations, and a queued pin notification that runs before the unregister event walks the dangling reference into dpll_device_ops(), triggering a WARN_ON and dereferencing a NULL pointer, which results in a kernel panic. The vulnerability yields a denial‑of‑service condition by crashing the system or a container running on top of it.
Affected Systems
All Linux kernel builds that include the dpll subsystem and were released before the commit that fixed the issue (33f016b23a219fe0… and fdbf04e3e01a872d…) are affected. This includes the default distribution kernels up to the point of the fix and any custom builds that have not applied the patch, regardless of distribution. All platforms that use the generic Linux kernel are potentially impacted.
Risk and Exploitability
The CVSS score is not published, but the EPSS score is less than 1 %, indicating a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog, and there is no publicly documented exploit. Attackers would need to trigger a specific sequence of driver unregistration events or load a malicious module that registers a dpll pin and then forces the corresponding device to unregister. Because the flaw manifests only at the kernel level and requires local privilege or access to load drivers, the overall risk is moderate, with the primary impact being a system crash (denial of service).
OpenCVE Enrichment