Impact
An improper error handling sequence in the Sunplus PHY driver’s initialization routine caused resources such as clocks and reset controls to remain allocated when failures occurred. This flaw could lead to resource exhaustion or unpredictable driver state, potentially affecting system stability. The patch restores the correct cleanup paths by returning immediately on clock‑enable failure, releasing the clock only if reset deassertion fails, and jumping to an error handler when voltage update fails, ensuring that no resources are leaked. The primary impact is therefore a resource leak that may manifest as driver instability or degraded performance.
Affected Systems
The vulnerability is present in any Linux kernel that includes the Sunplus PHY driver without the recent fix. No specific kernel version is listed in the CVE data, but the fix is attached to commit 1489b694b1f3265cd5363100642a22190033f4b0 (and related commits). Users running kernels that contain this commit are not affected.
Risk and Exploitability
The EPSS score is reported as <1 %, indicating a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in the CISA KEV list. While the flaw is not immediately exploitable as a pure attack vector, an attacker with local or kernel privileges could trigger the initialization path to consume resources iteratively, potentially causing a denial of service. It is inferred that an attacker would need to exercise local privileged or kernel mode execution to trigger the Sunplus PHY driver’s initialization routine, as the issue resides entirely within the kernel driver. Consequently, the risk is low but non‑zero, and patching is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA