Impact
The Linux kernel fails to destroy the NVMe admin queue allocated via blk_mq_alloc_queue() when a controller is removed during an initialization failure. Because blk_mq_exit_queue() is never called, the queue’s timeout timer and work remain active on a freed object, leading to an oops and kernel panic. This manifests as a system crash whenever the controller is torn down immediately after a failed start-up, potentially exposing the machine to an arbitrarily-initiated denial of service. The failure is a use‑after‑free style bug that results in a null pointer dereference inside blk_mq_timeout_work().
Affected Systems
All Linux kernel builds that contain the Apple NVMe driver prior to the commit that adds queue destruction are affected. The vendors listed are simply Linux kernels; no product version range is specified in the CNA data, so any unpatched kernel running the Apple NVMe driver is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 7.4 the vulnerability is considered high severity. The EPSS score of less than 1% indicates that, at present, the likelihood of exploitation is low, and it is not catalogued in the CISA KEV list. The attack vector would require a hardware or driver failure scenario that causes immediate teardown, or an attacker who can inject a malicious Apple NVMe device that triggers this crash path. Thus while the impact is severe, the probability of exploitation in the wild remains modest, but patching is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA