Impact
The AMD ISP4 driver in the Linux kernel contains a flaw where its initialization routine holds a non‑recursive mutex, ops_mutex. When an error occurs during initialization, the routine jumps to an error path that calls a teardown helper that attempts to reacquire the same mutex. Because the mutex cannot be re‑entered, the current thread blocks, creating a self‑deadlock. This deadlock can stall device initialization and, if the driver is critical to system operation, lead to a system‑wide halt or freeze, resulting in a denial of service.
Affected Systems
All Linux kernel builds that incorporate the AMD ISP4 driver and lack the patching commit 74669cc3483e9729ca26b4e06a096ccdd607db64 are affected. This includes the generic Linux:Linux distributions, OEM kernels, and custom builds that include the unpatched driver. Kernels that have integrated the fix commit or later are not vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The deadlock occurs only during kernel initialization or driver re‑initialization, requiring local kernel execution privileges; remote exploitation is not indicated by the description. An attacker with local privileges could trigger the failure path to cause the driver to deadlock, potentially resulting in a denial of service.
OpenCVE Enrichment