Impact
The Linux kernel tegra241 driver contains a race that publishes a virtual command queue (vcmdq) before the underlying command queue structure is fully built. An error interrupt service routine can fire while this incomplete pointer is visible, dereferencing a zeroed or NULL structure and causing a kernel panic. The failure results in a system crash and loss of service. The weakness is identified as a null pointer dereference (CWE‑476).
Affected Systems
Affected boots are Linux kernel builds that include the tegra241 platform driver, typically used on NVIDIA Tegra SoC devices. Any kernel that compiles the tegra241 driver before the fix—identified by the commit that moves vcmdq publishing to after full initialization—may crash when the error ISR occurs. Specific version numbers are not listed, so all pre‑fix kernels are vulnerable.
Risk and Exploitability
The EPSS score of <1% indicates that exploitation probability is low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require a local kernel scenario that can trigger the error ISR during the brief window when the vcmdq is not yet fully constructed, such as during boot or a forced kexec operation. Overall risk is moderate; a kernel crash leads to downtime and potential data loss.
OpenCVE Enrichment
Debian DLA
Debian DSA