Impact
The flaw resides in the Linux kernel’s coretemp hwmon driver, where the pdata->core_data array is allocated on first package but not freed when the CPU lacks package thermal support (PTS). Over time, repeated loading and unloading of the module can accumulate unused kernel memory, potentially exhausting memory and degrading system stability or causing denial of service. The leak does not provide a direct code execution vector, but may expose sensitive kernel data if the memory is not zeroed.
Affected Systems
All installations of the Linux kernel that include the coretemp hwmon driver and run on CPUs without PTS support are affected. The issue manifests in systems with Intel CPUs that do not expose package thermal sensor support. The exact kernel version is not specified, but the patch is part of the upstream kernel and applies to all affected releases.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of current exploitation. Nonetheless, because the flaw is local and requires the coretemp driver to be loaded, an attacker with local privileges could trigger the memory leak by repeatedly inserting and removing the module, potentially leading to resource exhaustion. The CVSS score is not provided, but the impact aligns with medium severity due to resource depletion and potential availability loss.
OpenCVE Enrichment
Debian DLA
Debian DSA