Impact
The vulnerability involves errors in the Linux kernel’s stm32 DCMI media driver during probe(). The bug causes a null pointer dereference by calling dma_release_channel on an uninitialized pointer, which can lead to a kernel crash. Additionally, the code fails to clean up allocated resources on error paths, resulting in memory leaks. These issues are triggered during driver initialization and do not require special conditions beyond loading the driver.
Affected Systems
The affected systems are Linux kernel builds that include the stm32 DCMI driver. Specific version ranges are not identified in the advisory, so all kernel releases prior to the patch that contain the described code are potentially impacted. The vulnerability is present on any platform that compiles this driver, regardless of distribution.
Risk and Exploitability
The EPSS score indicates that the likelihood of exploitation is very low (<1%). The vulnerability is not listed in the CISA KEV catalog, reflecting limited widespread exploitation. Because the flaw occurs in kernel initialization, an attacker must be able to load or trigger the driver, which typically requires local or privileged access. The absence of a CVSS score limits precise severity quantification, but the potential for a system crash warrants prompt mitigation.
OpenCVE Enrichment