Impact
The flaw originates from a race condition in the regulator subsystem of the Linux kernel. A delayed work task intended to disable unused I2C‑controlled regulators runs on a non‑freezable work queue, allowing it to execute while the system is in the middle of a suspend transition. When this task attempts to write to a device via I2C after the adapter has already been suspended, the kernel generates a warning and can potentially leave the device or regulator in an inconsistent state, leading to functional degradation or system instability.
Affected Systems
The issue affects the generic Linux kernel, as indicated by the vendor and product names. No specific kernel version range is provided, so any kernel that contains the affected code path before the patch may be vulnerable.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The race condition requires the system to be transitioning to suspend, limiting the attack scenarios to a local boot or power cycle that occurs during that window. While exploitation is unlikely, the impact on service availability can still be significant on vulnerable systems.
OpenCVE Enrichment
Debian DLA
Debian DSA