Impact
The bug exists in the DRM sun4i TCON driver within the Linux kernel, where a reference obtained via of_find_device_by_node() to the TCON TOP node is never released after successful mux configuration. The unreleased reference keeps kernel objects alive, leading to a kernel‑space memory leak. Repeated driver reloads or configuration changes can amplify the leak, consuming kernel memory and potentially causing system instability or a crash.
Affected Systems
Any Linux kernel build that contains the sun4i TCON driver code compiled before the patch that added the reference drop is impacted. The vendor is Linux and the product is the Linux kernel; no specific version list is supplied, so any pre‑patch build that includes the affected driver remains vulnerable.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. The risk to local systems depends on how frequently the driver can be reconfigured or reloaded. The likely attack vector is local or remote code that triggers repeated mux configuration or driver reload, but the need for sustained activity to exhaust kernel memory means that exploitation would likely lead to a denial‑of‑service rather than code execution or privilege escalation. The CVSS score is not provided, which further implies that the severity is moderate rather than critical.
OpenCVE Enrichment
Debian DLA
Debian DSA