Impact
The vulnerability resides in the DRM driver for the sun4i CRTC in the Linux kernel. In sun4i_crtc_init the function returns a plain NULL when layer initialization fails, while all other error paths return an error pointer. The caller, sun4i_tcon_bind, checks the result with IS_ERR and incorrectly treats NULL as handled, setting tcon->crtc to NULL. Later calls such as sun4i_rgb_init or sun4i_lvds_init dereference this NULL pointer in drm_crtc_mask(), causing a kernel oops and crash. This is a classic null‑pointer dereference (CWE‑476) and gives an attacker the possibility to trigger a denial of service by crashing the kernel.
Affected Systems
The flaw affects all Linux kernel builds that contain the sun4i DRM driver before the patch. It applies to any distribution that includes this driver as part of the kernel. The exact affected releases are not listed, so any kernel incorporating the unpatched sun4i_crtc_init code is at risk.
Risk and Exploitability
The EPSS score is reported as < 1%, indicating a very low probability of exploitation at the time of this advisory, and the vulnerability is not listed in CISA's KEV catalog. The attack likely requires local or privileged access, such as supplying malformed DRM inputs or interacting with the device during initialization. Because the flaw does not expose an externally reachable code path, remote exploitation is unlikely, but a local attacker with discretionary access to the DRM subsystem could force a crash, leading to downtime. Overall the risk is modest but non‑negligible; patching removes the weakness entirely.
OpenCVE Enrichment
Debian DLA
Debian DSA