Impact
During initialization of the ACPI processor driver in the Linux kernel a cpufreq policy notifier is registered before the driver and CPU hotplug state are fully set up; if either the driver_register or cpuhp_setup_state calls fail the error path cleans up the driver but fails to unregister the cpufreq notifier, leaving it registered with a dangling reference to a partially initialized driver, which may later be invoked by CPU frequency change events and can cause a kernel panic or crash, effectively denying service.
Affected Systems
Linux kernel on all supported distributions and versions, as indicated by the vendor/product entry and the general CPE string. No specific version constraints are provided, so all released kernel branches may be impacted until the fix is integrated.
Risk and Exploitability
The EPSS score of < 1 % indicates that exploitation in the wild is very unlikely and the vulnerability is not listed in CISA KEV; however the flaw can be triggered by an init failure, which may be provoked by misconfiguration or malicious manipulation of the ACPI interface, and can lead to a kernel crash, so administrators should consider it a high‑impact concern despite the low probability of exploitation. It is inferred that the attack vector would require local or privileged access to the system to influence ACPI initialization or CPU frequency changes.
OpenCVE Enrichment
Debian DLA
Debian DSA