Impact
The Linux kernel DRM MSM DSI driver called dev_pm_opp_set_rate(0), which removes a power vote but does not park the clock, allowing the device to run without proper power support. This mismatch can lead to hardware damage or kernel instability, effectively denying service to systems that rely on the DSI link. The weakness is improper resource management (CWE‑404).
Affected Systems
Linux kernel (all releases) – the vulnerability is present in the DRM MSM DSI driver across all Linux kernel builds.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. No CVSS score is provided, but the lack of known exploitation events and low EPSS suggest limited immediate risk. Exploiting this bug would require privileged or kernel‑module access, which is not trivially available to remote attackers. The bug was addressed by removing the explicit call to dev_pm_opp_set_rate(0).
OpenCVE Enrichment
Debian DLA
Debian DSA