Impact
A flaw in the Linux kernel ACPI subsystem causes an incomplete rollback when an ACPI device fails to be added after its instance ID and bus ID have been allocated. The rollback path removes only the wakeup list while leaving the bus‑ID bookkeeping in place, which permanently consumes the instance number. Over time, this leaks identifier resources, potentially exhausting the pool of available bus IDs and preventing new ACPI devices from being enumerated.
Affected Systems
All Linux kernel releases that predate the ACPI bus‑ID cleanup fix, i.e., the mainline Linux kernel versions that do not include the commit that introduces the helper for bus‑ID and wakeup‑list cleanup.
Risk and Exploitability
The vulnerability does not provide for code execution or privilege escalation. Exploitation requires the attacker to cause a device_add failure, typically under privileged or boot conditions. The EPSS score is reported as less than 1 %, and the flaw is not listed in the CISA KEV catalog, indicating a low probability of real‑world exploitation. Nonetheless, repeated failures could lead to service disruption by exhausting ACPI bus ID resources.
OpenCVE Enrichment
Debian DLA
Debian DSA