Impact
The Linux kernel’s IOMMU DMA allocation code can fault when the non‑blocking, non‑coherent path calls dma_alloc_from_pool(). The routine returns the allocated page only on success and sets cpu_addr accordingly, but the kernel mistakenly uses cpu_addr to detect failure. If cpu_addr is NULL and the returned page is NULL or invalid, the kernel may attempt an IOMMU mapping on an unreachable address, leading to a NULL pointer dereference and an OOPS or kernel panic, which in turn provides a denial of service. The weakness manifests as a classic null‑pointer dereference.
Affected Systems
The flaw resides in all Linux kernel builds that have not yet incorporated the patch found on the kernel git tree. Consequently, every system that runs a current Linux kernel and exercises the iommu/dma non‑blocking allocation path could be affected, including generic servers, embedded devices, and virtualized guests that rely on direct device access.
Risk and Exploitability
The vulnerability has a high CVSS score of 7.8. The EPSS score of less than 1% indicates a low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. An attacker would need to trigger local kernel code execution or load a module that calls dma_alloc_from_pool without checking the returned page. If such an action is performed, the kernel may crash, which in turn results in denial of service. No evidence suggests this leads to privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA