Impact
A kernel driver for the AD5686 digital‑to‑analog converter performs a NULL check on its match data pointer. If an attacker exploits the driver_override mechanism via sysfs with a nonexistent device name, the match data becomes NULL and the driver dereferences it. This causes an uncontrolled kernel dereference that can crash the system. The likely attack vector is a local user writing to sysfs, and the immediate impact is a denial of service, as the kernel may panic or reset, requiring a reboot to restore service. No confidential data is disclosed and no persistent attacker advantage is gained beyond destabilizing the host.
Affected Systems
All Linux kernel installations that lack the fix for the AD5686 DAC driver, i.e. any kernel before the patch introduced in commit cdaa9cb. The vulnerability applies across all vendor builds of the Linux kernel that include this driver module.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local write access to sysfs, and a determined user can trigger a kernel crash. The CVSS score is not provided, but the presence of an unhandled NULL dereference, together with the ability to invoke it locally, places the risk at moderate to high if the attacker can access sysfs. Mitigation through kernel update or restricting sysfs write permissions would eliminate the risk.
OpenCVE Enrichment