Impact
The vulnerability is a NULL pointer dereference in the Linux kernel’s AMD P-state cpufreq driver. When a CPU hot‑plug event or driver teardown removes the policy associated with a particular CPU, calls to cpufreq_cpu_get() can return NULL. The subsequent unguarded use of the returned pointer by amd_pstate_power_supply_notifier() and amd_pstate_set_epp() causes a kernel fault, likely leading to a crash and a system reboot. This results in a denial of service for the affected host. The flaw reflects a null pointer dereference weakness, which is in the category of CWE-476.
Affected Systems
Linux kernel installations prior to the commit that added the missing policy checks are vulnerable. The issue applies to all kernels that include the AMD P-state cpufreq driver without the patched guard. Because the kernel is the core of the operating system, all userspace processes run with the privileges of the kernel and are indirectly affected by a crash. No specific distribution or kernel release is listed, so all affected builds should be checked for the presence of the cited commit and updated accordingly.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The attack vector is inferred to be local or privileged, as the flaw is within kernel code and requires the ability to trigger a CPU hot‑plug or driver teardown event. The impact is significant—a crash—which is mitigated by applying the patch. Given the low EPSS and lack of public exploits, the overall risk is moderate but the cost of a system reboot can be high. The security community has not reported active exploits for this flaw to date.
OpenCVE Enrichment