Impact
This vulnerability exists in the MediaTek clock driver within the Linux kernel. During the error path of the mtk_clk_register_pllfhs function, the driver attempts to clean up registered PLLs but fails to unmap the IO memory assigned to the fhctl node. The missing unmap operation creates a persistent leak of kernel IO memory. If the function continues to be invoked repeatedly or in environments with repeated hardware reinitializations, the cumulative leaked memory can grow until the kernel can no longer map additional resources, potentially leading to instability or denial of service. Affected systems are Linux kernels compiled with the MediaTek clock support present. The patch is integrated into the mainline kernel codebase and applies to all versions of the kernel that include the mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs routines. Exact version ranges are not specified in the advisory, but any kernel prior to the commit referenced in the advisory is considered vulnerable. The CVSS score is not provided, and the EPSS score is noted to be under 1 %. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require access to the kernel module subsystem or privileged boot configuration that allows loading of the MediaTek driver, so the likelihood of attack is low in typical non‑root scenarios. Nevertheless, the resource exhaustion effect could impact availability if left unpatched in systems that use the affected drivers frequently.
Affected Systems
The flaw resides in the MediaTek clock driver (mtk_clk) within the Linux kernel. Linux kernel builds that include MediaTek clock support are affected. The advisory does not specify exact version ranges, but any kernel release that contains the mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs routines prior to the commit referenced in the advisory is considered vulnerable.
Risk and Exploitability
The CVSS score is not disclosed in the advisory, but the EPSS score of less than 1 % indicates a low probability of active exploitation, and the vulnerability is not recorded in CISA’s KEV catalog. Exploitation would require privileged interaction with the kernel, such as loading or reinitializing the MediaTek clock driver, which is typically restricted to system administrators or boot configurations. If an attacker can trigger repeated failures in the register_pllfhs function, the accumulated IO memory leak could exhaust available kernel space, potentially leading to kernel memory exhaustion and a denial‑of‑service. In practice, the threat is limited to environments that frequently load or re‑enable the affected driver.
OpenCVE Enrichment