Impact
The vulnerability is in the Linux kernel MHI host driver. When a controller is registered, the driver creates a device instance and then attempts to add an optional trigger edl sysfs file. If the sysfs creation fails, the code drops only the device reference but leaves the device registered, resulting in a dangling registration that can cause resource leakage or instability during subsequent driver operations.
Affected Systems
Affected systems include all versions of the Linux kernel that contain the unpatched MHI host driver before the commit that added cleanup logic. The issue is present in every distribution build that employs the buggy registration code and is not limited to a particular release series.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of current exploitation. Based on the description, it is inferred that an attacker would need local or privileged access, such as the ability to load a kernel module or manipulate the MHI subsystem, to repeatedly trigger the faulty registration path. If achieved, repeated failures could exhaust kernel resources or lead to driver instability, potentially resulting in a denial‑of‑service condition.
OpenCVE Enrichment
Debian DLA
Debian DSA