Impact
The vulnerable function pinctrl_generic_to_map reads device tree data and allocates internal pinctrl maps. If any subsequent pinctrl helper routine fails, the code returns an error without freeing previously allocated map entries. This results in a memory leak that propagates to all drivers that use pinctrl_generic_to_map, causing the kernel memory pool to be exhausted over time. The exposed weakness is a classic memory‑allocation error and can lead to a denial‑of‑service condition when the kernel runs out of address space or allocation bandwidth.
Affected Systems
The flaw resides in the Linux kernel. All installations that load the generic pinctrl driver and invoke pinctrl_generic_to_map during boot or driver initialisation are affected. The issue may surface on a wide range of embedded or desktop platforms that use kernel blobs compiled with the generic pinctrl backend.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation under current conditions, and the vulnerability is not listed in any KEV catalog. Likely exploitation requires the attacker to influence device tree configuration or to trigger repeated failures in pinctrl_generic_to_map, which typically demands elevated or privileged access to the system. As a result, the risk remains moderate for environments that rely on dynamic or user‑controlled DT entries, while the risk is low for static, provider‑controlled configurations. The impact is a bit‑rot style memory depletion that could eventually crash the system, but it is unlikely to allow arbitrary code execution.
OpenCVE Enrichment