Impact
The flaw in the FireWire subsystem causes a memory leak when build_tree() encounters an invalid identifier sequence. Node objects that are created as part of parsing the tree are not removed from the linked list on error, resulting in unreferenced kernel memory remaining allocated until the system eventually runs out of memory or the kernel is reloaded.
Affected Systems
This issue affects the Linux kernel’s FireWire core driver. All kernel versions that include the build_tree() function in the firewire module are subject to the leak; specific release numbers are not listed in the advisory, so any installed kernel that has not yet received the patch is vulnerable.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The absence of a CVSS score suggests that the impact is primarily denial‑of‑service through resource exhaustion rather than direct privilege escalation. Attacks would likely require the ability to send malformed FireWire packets or otherwise trigger the error path, suggesting a local or device‑level attack vector. Given these constraints, the overall risk is moderate but mitigable by applying the kernel patch.
OpenCVE Enrichment
Debian DLA
Debian DSA