Impact
The flaw lies in the Linux kernel’s amd_pstate_ut module, which can be manually loaded with modprobe. When the module is loaded on hardware that is not powered by an AMD processor, the code path that checks whether the amd_pstate driver is active is bypassed, causing a NULL pointer dereference and resulting in a kernel panic. The immediate effect is a denial of service, as the system reboot or become unusable. The vulnerability does not provide a direct remote code execution pathway, but the crash can be triggered by any user with permission to load kernel modules, typically requiring elevated privileges.
Affected Systems
The issue affects any installation of the Linux kernel that includes the amd_pstate_ut module and runs on non‑AMD platforms, such as Intel x86 servers or workstations. No specific kernel version is cited, so it applies to current kernel releases that ship the module until the patch that introduces state detection is deployed.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the lack of exploitation and the requirement for module‑loading privileges suggest a moderate risk. Attackers would need root or module‑load capability to trigger the crash, making it a local denial‑of‑service risk rather than a remote attack vector.
OpenCVE Enrichment