Impact
In the Linux kernel, the Intel int3400 thermal driver does not properly remove ODVP (overdrive temperature package) sysfs files and associated memory when a probe fails after evaluate_odvp() but before the cleanup_odvp() routine is executed. The existing unwind path only deletes these objects in a late sysfs failure point, leaving orphaned entries and cached pointers. This creates a resource‑leak scenario that can accumulate over time, potentially exhausting kernel resources and causing system instability. The flaw arises from missing cleanup of system state after a partial failure.
Affected Systems
The vulnerability affects any Linux system that loads the Intel int3400 thermal driver. Specific kernel versions are not listed in the advisory, so all kernels that register this driver and experience probe failures after evaluate_odvp() could be impacted. Administrators should verify whether their installed kernel includes the int3400 driver and whether a newer kernel release contains the patch.
Risk and Exploitability
The CVSS score of 7 indicates a moderately high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the vulnerability can be triggered by a local or privileged user during boot or module loading when a probe failure occurs. The impact is limited to a resource leak and potential instability, with no direct code‑execution pathway or known remote exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA