Impact
A flaw in the Linux kernel’s UFS SCSI driver causes a null pointer dereference in the completion queue entry handling routine when an invalid tag is encountered. The warning‑logging path references the completion queue entry regardless of its validity, leading to a kernel panic and system shutdown. The weakness is a classic NULL pointer dereference, identified as CWE‑476, and does not provide direct code execution but can be leveraged to cause a denial of service for a local or privileged attacker.
Affected Systems
The vulnerability affects all Linux kernel releases that have not incorporated the fixes from commits 331bda797e6afc143127ce72b1469d73316f49b4 and a769095d1d74ebac2b1474c56bbd29bb0b9ed5a7. No specific version range is listed, so any kernel build lacking these patches is potentially impacted.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low likelihood of widespread exploitation, and the issue is not currently listed in CISA’s KEV catalog. Exploitation requires a malformed UFS command or direct interaction with the driver, which is typically a local or privileged attack vector. If successfully triggered, the crash results in kernel instability, making this a moderate‑to‑high severity denial of service rather than a full remote code execution threat.
OpenCVE Enrichment