Impact
A bug in the Linux kernel cryptographic driver "keembay" causes a completion object to be used before it is initialized. When an IRQ is requested while the completion is still uninitialized, an interrupt can be delivered to the handler, which calls complete() on an uninitialized object. This leads to undefined behavior, typically a deadlock or corruption of synchronization state, that can prevent normal kernel operation and result in a denial of service.
Affected Systems
The flaw resides in the Linux kernel itself; no specific kernel release is listed in the advisory. Any Linux distribution using a kernel build that includes the keembay driver before the patch is potentially affected.
Risk and Exploitability
The exploitability of this issue is low. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attacking would require triggering an interrupt during the narrow window when the IRQ is registered but the completion remains uninitialized, a scenario that typically demands kernel‑level privileges or physical access. The primary consequence is a potential denial of service by interrupt‑handling failure rather than remote code execution or data exfiltration.
OpenCVE Enrichment
Debian DLA
Debian DSA