Impact
The vulnerability arises when the mailbox driver for Qualcomm CPuCP attempts to send a message with a NULL data pointer. A NULL pointer dereference in the send_data callback triggers a kernel panic, effectively shutting down the system. The defect is triggered when mailbox_clear_channel() calls mbox_send_message() with NULL data to notify that a receive channel has been cleared. The code path that performs the dereference is exercised under PREEMPT_RT real‑time scheduling. Based on the description, the likely attack vector is a locally privileged process that can cause a mailbox channel to be cleared, leading to a crash; no remote exploitation is reported.
Affected Systems
All Linux kernel installations that include the Qualcomm CPuCP mailbox driver are affected. The issue is specific to the qcom_cpucp mailbox implementation and affects all kernel versions prior to the application of the patch adding the NULL check. No particular vendor or distribution version is listed, so any kernel with this driver exposed is at risk.
Risk and Exploitability
The CVSS score is not explicitly given, but the EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is local and requires the ability to trigger a mailbox channel clear, which usually implies restricted or privileged access to the kernel mailbox facilities. While exploitation is straightforward once the triggering action is performed, the low EPSS score suggests that active exploitation in the wild is unlikely at present.
OpenCVE Enrichment
Debian DLA
Debian DSA