Impact
In the Linux kernel, a deadlock occurs in the nfcon console driver on m68k architectures when nfcon_device() calls console_is_registered() while holding console_list_lock. The erroneous call attempts to acquire the same lock again, causing the kernel to stall. An attacker who can trigger this path can force the entire system into an unavailable state. The weakness is an instance of improper synchronization leading to deadlock.
Affected Systems
The vulnerability affects m68k kernels that include the nfcon console module prior to the fix commit 7c2af0f634f1. All distributions using these kernel versions are at risk; newer releases that removed the console_is_registered() check are not affected.
Risk and Exploitability
The deadlock yields a high‑impact denial of service, but exploitation requires a local or privileged attacker who can invoke nfcon_device(). The EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the issue is not listed in the CISA KEV database. The expected attack vector is local kernel tampering or code injection that reaches the console path.
OpenCVE Enrichment
Debian DLA
Debian DSA