Impact
A flaw in the Linux kernel’s interrupt controller (GIC v3 ITS) causes a resource leak when the interrupt domain allocation function fails. The cleanup routine does not release the interrupt resources that were reserved earlier, leaving them dangling. This deficiency can lead to gradual exhaustion of kernel resources. The weakness matches CWE-772. The description confirms that the kernel developers have introduced a fix that invokes the proper teardown on error paths.
Affected Systems
All Linux kernel installations that use the GIC v3 ITS module and have not applied the recent patches will be affected. The vendor list indicates the Linux kernel itself; specific affected release numbers are not enumerated in the advisory, so any kernel revision before the fix could potentially be vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity while the EPSS score of <1% suggests a very low exploitation probability in the current landscape. The vulnerability is not listed in CISA’s KEV catalog, implying there are no publicly documented exploits. An attacker would need to execute code with kernel-level privileges or induce repeated allocation failures locally, which is not directly documented in the description but is inferred from the nature of the resource leak. Based on the description, it is inferred that repeated allocation failures could cause resource exhaustion, potentially leading to a denial-of-service scenario. The flaw does not provide arbitrary code execution, so the risk level is moderate but still warrants an update to the fixed kernel to avoid potential denial-of-service.
OpenCVE Enrichment
Debian DLA
Debian DSA