Impact
Each time the imx6q cpufreq driver is probed, it allocates a memory array with devm_kcalloc tied to a CPU device that is never unbound. Because the driver’s removal routine does not free this allocation, the array stays allocated for the life of the system. Repeated probing therefore accumulates unused memory blocks, which can lead to overall resource exhaustion and weaken system stability.
Affected Systems
The flaw affects Linux kernel implementations that include the imx6q cpufreq driver on i.MX 6 quad SoC platforms. All kernel builds that expose this driver without the patch are vulnerable; any system running such a kernel—particularly embedded devices or virtualized environments using the i.MX6UL architecture—falls within the affected set.
Risk and Exploitability
EPSS for this issue is reported as below 1 % and it is not listed in the CISA KEV catalog, indicating a very low probability of active exploitation. The flaw requires interaction that causes the driver to rebind, a condition that typically occurs only during system reboot or manual driver reload. Absent such an event, the vulnerability does not pose an immediate threat to an attacker. However, long‑term use of an unpatched kernel may lead to stability problems through gradual memory depletion.
OpenCVE Enrichment
Debian DLA
Debian DSA