Impact
The vulnerability involves a missing hook for IRQ resource helpers in the Linux kernel’s airoha pinctrl driver. Because the .irq_request_resources method is not invoked, the framework fails to set the GPIOD_FLAG_USED_AS_IRQ flag. This oversight breaks the kernel’s pin direction locking mechanism, permitting userspace applications or other kernel modules to reconfigure an active IRQ pin as an output. This could be exploited to alter the electrical behavior of the hardware, potentially disabling interrupts or causing unexpected data flows, which provides avenues for privilege escalation or denial of service.
Affected Systems
This flaw affects the Linux kernel itself. The affected vendor/product list reads Linux:Linux twice; version specifics are not disclosed, so any kernel build that includes the airoha pinctrl driver is potentially impacted until patched.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability (<1%) and the vulnerability is not listed in CISA’s KEV catalog. No CVSS figure is supplied, but the defect grants the ability to reconfigure critical hardware lines, which is a high‑severity impact if an attacker can reach a privileged context. The likelihood of an attack relies on successfully exploiting the missing flag; from the description it is inferred that the attacker must have the ability to load an alternate kernel module or invoke a driver that manipulates the IRQ pin. As the attack vector is internal to the kernel, only privileged users or compromised drivers can trigger it, reducing the exposure to low‑level. Nonetheless the potential impact warrants close attention.
OpenCVE Enrichment